VYPR
Unrated severityNVD Advisory· Published Apr 8, 2021· Updated Nov 8, 2024

Cisco Small Business RV Series Routers Vulnerabilities

CVE-2021-1473

Description

Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco Small Business RV Series Routers web-based management interface contains multiple vulnerabilities allowing remote command execution or authentication bypass.

Vulnerability

The web-based management interface of Cisco Small Business RV Series Routers contains multiple vulnerabilities (CVE-2021-1473). These flaws exist in the handling of HTTP requests by the device's management interface, enabling a remote attacker to execute arbitrary commands or bypass authentication and upload files on an affected device. The affected products include RV160, RV260, RV340, RV345, and RV345P routers running firmware versions prior to the fixed releases specified in the Cisco advisory.

Exploitation

An attacker can exploit these vulnerabilities by sending specially crafted HTTP requests to the targeted device's web-based management interface. The attacker does not need prior authentication to exploit the authentication bypass and file upload flaws. For the command execution vulnerability, some level of access may be required, but the exact preconditions are not fully detailed in the available references. No user interaction is required beyond the device's web interface being accessible over the network.

Impact

Successful exploitation could allow an attacker to bypass authentication and gain administrative access to the router, upload arbitrary files, or execute arbitrary commands with elevated privileges. This can lead to full compromise of the device, including disclosure of sensitive information, modification of device configuration, and potential use as a pivot point for further network attacks.

Mitigation

Cisco has released free software updates to address these vulnerabilities. Customers should upgrade their devices to the fixed firmware versions as specified in the Cisco Security Advisory [1]. No workarounds are mentioned; the recommended course of action is to apply the patch. The advisory also provides instructions for customers without service contracts to obtain the fixed software from Cisco TAC.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.