Appsecure logo

CVE-2021-1149: High Vulnerability in Cisco Small Business Routers

Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers are affected by a high-severity vulnerability that allows command injection by authenticated attackers. Immediate action is required for organizations using these devices to mitigate risks.

HIGHCVSS 7.2 · Published January 13, 2021

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

Cisco has identified multiple vulnerabilities in the web-based management interface of its Small Business RV110W, RV130, RV130W, and RV215W Routers. These vulnerabilities could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The critical nature of this vulnerability arises from improper validation of user-supplied input in the web management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to a targeted device, potentially gaining root access to the underlying operating system.

The severity of this vulnerability is classified as high, with a CVSS score of 7.2. This means that the potential impact is significant, allowing attackers to execute arbitrary code as the root user on affected devices. Organizations using these routers should be aware that the exploitation of this vulnerability would require valid administrator credentials, thereby emphasizing the importance of credential security.

As of now, Cisco has not released any software updates to address these vulnerabilities. Given the risk to organizations, it is crucial to assess the security posture surrounding these devices and take necessary precautions to prevent unauthorized access. Organizations should prioritize patching immediately.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.