ZeroHour

CVE-2018-0125

KEVmoderate

Unauthenticated RCE in Cisco RV132W and RV134W VPN Routers

CISA: Cisco VPN Routers Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
55%p99
Published
()
KEV added
AI analysis

CVE-2018-0125 is a critical (CVSS 9.8) input-validation flaw in the web interface of Cisco's RV132W ADSL2+ and RV134W VDSL2 small-business VPN routers. An unauthenticated remote attacker can trigger it by sending a crafted HTTP request to the device's web management interface, which inadequately validates user-controlled input. A successful exploit lets the attacker execute arbitrary code with root privileges and take full control of the router, or alternatively crash the device into a denial-of-condition. Only these two small-business router models are affected; the flaw is fixed in firmware version 1.0.1.11. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog (March 2022) and is being actively exploited in the wild, with a high predicted exploitation probability (EPSS ~55%).

What to do: Upgrade affected RV132W and RV134W routers to firmware version 1.0.1.11 or later per Cisco's guidance. Until patched, restrict the web management interface to trusted networks (avoid exposing it to the internet) and check whether your devices are on the CISA KEV list requiring remediation. After patching, review device integrity, as a successful exploit grants full root-level control of the router.

Affected
Cisco RV132W ADSL2+ Wireless-N VPN Router firmwareall versions prior to 1.0.1.11
Cisco RV134W VDSL2 Wireless-AC VPN Router firmwareall versions prior to 1.0.1.11
Estimated exposure
moderateroughly several thousand internet-exposed devices (installed base likely higher; SOHO/small-office deployments) — These are small-business VPN routers typically deployed at single sites, and public internet scans of Cisco RV-series small-business routers historically show thousands of exposed management interfaces, so exposure is estimated at the low…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to an incomplete input validation on user-controlled input in an HTTP request to the targeted device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to execute arbitrary code as the root user and gain full control of the affected system or cause it to reload, resulting in a DoS condition. This vulnerability is fixed in firmware version 1.0.1.11 for the following Cisco products: RV132W ADSL2+ Wireless-N VPN Router and RV134W VDSL2 Wireless-AC VPN Router. Cisco Bug IDs: CSCvg92737, CSCvh60170.

CISA Known Exploited Vulnerability
Affected
Cisco VPN Routers
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
rv132w firmware, rv134w firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news