Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Arbitrary File Upload Vulnerability
92Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 5.3epss 89%
from disclosure to weapon135 days
Published on NVDApr 5
1st PoC+135d
VulnCheck+224d
exploitation probability
89%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization enforcement mechanisms in the context of file uploads. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to upload arbitrary files to the affected device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products
Cisco · Cisco Small Business RV Series Router Firmwarepublic PoCs found — 1
vulncheckvulncheck.com/xdb/edfd82844be4unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.