CVE-2021-1400

HIGH

Cisco Small Business WAP125/131/150/351/361/581 Firmware - Authenticated Info Disclosure & Command Injection

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to obtain sensitive information from or inject arbitrary commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN71263107/index.html

Scores

CVSS v3 8.8
EPSS 0.0049
EPSS Percentile 65.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (6)
cisco/wap125_firmware < 1.0.3.1
cisco/wap131_firmware < 1.0.2.17
cisco/wap150_firmware < 1.1.2.4
cisco/wap351_firmware < 1.0.2.17
cisco/wap361_firmware < 1.1.2.4
cisco/wap581_firmware < 1.0.3.1
Published May 06, 2021
Tracked Since Feb 18, 2026