Description
Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allow remote attackers to replace the configuration file via an upload request to an unspecified URL, aka Bug ID CSCtw55495.
References (2)
Core 2
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120223-srp500
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1026736
Scores
EPSS
0.0120
EPSS Percentile
65.0%
Details
CWE
CWE-264
Status
published
Products (18)
cisco/small_business_srp520-u_series_firmware
1.1.0
cisco/small_business_srp520_series_firmware
1.01.01
cisco/small_business_srp520_series_firmware
1.01.09
cisco/small_business_srp520_series_firmware
1.01.11
cisco/small_business_srp520_series_firmware
1.01.19
cisco/small_business_srp520_series_firmware
1.01.23
cisco/small_business_srp520_series_firmware
< 1.01.24
cisco/small_business_srp521w
cisco/small_business_srp521w-u
cisco/small_business_srp526w
... and 8 more
Published
Feb 25, 2012
Tracked Since
Feb 18, 2026