Record summary

CVE-2021-34730 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC. VulnCheck reports CVE-2021-34730 use in known ransomware campaigns.

Description

A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of incoming UPnP traffic. An attacker could exploit this vulnerability by sending a crafted UPnP request to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a DoS condition. Cisco has not released software updates that address this vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 22, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 7, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Cisco Small Business RV Series Router Firmware

Browse Cisco / Cisco Small Business RV Series Router Firmware
CVE ListVersion range not suppliedaffected

application_extension_platform

Browse Cisco / application_extension_platform
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubbadmonkey7/CVE-2021-34730Repository PoCby badmonkey7Stars: 28Not analyzed17 files

1.4 MiB

GitHub

PoC details

References

2