CVE-2018-0127
Cisco RV Series Routers Exposure of Sensitive Information to an Unauthorized Actor
Record summary
CVE-2018-0127 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to the absence of user authentication requirements for certain pages that are part of the web interface and contain confidential information for an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device and examining the HTTP response to the request. A successful exploit could allow the attacker to view configuration parameters, including the administrator password, for the affected device. Cisco Bug IDs: CSCvg92739, CSCvh60172.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 15, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 2, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
RV Series RoutersBrowse Cisco / RV Series Routers | VulnCheck | Version data not supplied | |
Cisco RV132W and RV134W Wireless VPN Routers | CVE List | Cisco RV132W and RV134W Wireless VPN Routers | affected |
Nuclei templates
1ProjectDiscoveryCRITICALCisco RV132W/RV134W Router - Information DisclosureCVSS 9.8
Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an affected device via the web interface, which could lead to the disclosure of confidential information.
Impact
An attacker can exploit this vulnerability to gain sensitive information from the router.
Remediation
Apply the latest firmware update provided by Cisco to fix the vulnerability.
Source: ProjectDiscovery