CVE-2021-1156
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.
EPSS 0.03% · 10.6th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | application_extension_platform | 1.0.3.55 |
| cisco | rv130w_firmware | 1.2.2.8, 1.3.1.7 |
| cisco | rv215w_wireless-n_vpn_router_firmware | 1.3.1.7, 1.2.2.8 |
| cisco | rv130_vpn_router_firmware | 1.3.1.7, 1.2.2.8 |
| cisco | rv110w_firmware | 1.2.2.8, 1.3.1.7 |
| Cisco | Cisco Small Business RV Series Router Firmware | * |
Exploit Intelligence
Timeline
- Jan 13, 2021 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score