CVE-2014-2177
Cisco RV Router Firmware - Authenticated Remote Code Execution via Network-Diagnostics Interface
Title source: llmDescription
The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote authenticated users to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCuh87126.
References (6)
Core 6
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141105-rv
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/128992/Cisco-RV-Overwrite-CSRF-Command-Execution.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98497
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Nov/6
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/533917/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031171
Scores
EPSS
0.0258
EPSS Percentile
83.3%
Details
CWE
CWE-94
Status
published
Products (7)
cisco/rv120w
cisco/rv120w_firmware
< 1.0.5.8
cisco/rv180
cisco/rv180_firmware
< 1.0.3.10
cisco/rv180w
cisco/rv220w
cisco/rv220w_firmware
< 1.0.5.8
Published
Nov 07, 2014
Tracked Since
Feb 18, 2026