VDB

CVE-2021-34730

CVE-2021-34730 PUBLISHED CVSS 9.800000190734863 CRITICAL

A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of incoming UPnP traffic. An attacker could exploit this vulnerability by sending a crafted UPnP request to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a DoS condition. Cisco has not released software updates that address this vulnerability.

EPSS 26.35% · 96.4th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
26.35%
96.4th percentile

Affected Products

VendorProductVersions
CiscoCisco Small Business RV Series Router Firmwaren/a
ciscorv110w_wireless-n_vpn_firewall_firmware
ciscorv130_vpn_router_firmware
ciscorv215w_wireless-n_vpn_router_firmware
ciscorv130w_wireless-n_multifunction_vpn_router_firmware
CiscoN/A
ciscoapplication_extension_platform1.0.3.55, 1.0.3.55

Exploit Intelligence

…and 14 more exploits

Timeline

  • Jan 19, 1970 VulnCheck XDB Entry
  • Aug 18, 2021 CVE Published
  • Aug 19, 2021 EPSS Score
  • Oct 11, 2021 EPSS Score
  • Oct 16, 2021 EPSS Score
  • Oct 25, 2021 PoC Published
  • Jan 6, 2022 EPSS Score
  • Feb 10, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jun 7, 2022 EPSS Score
  • Jun 22, 2022 VulnCheck KEV Exploitation
  • Oct 3, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›