We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2018-0404

Cisco RV180W Wireless-N Multifunction VPN Router SQL Injection Vulnerability



Description

A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The attacker could retrieve sensitive information which should be restricted. A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The attacker could retrieve sensitive information which should be restricted. The product has entered the end-of-life phase and there will be no more firmware fixes.

Reserved 2017-11-27 | Published 2018-10-05 | Updated 2024-11-26 | Assigner cisco

Problem types

CWE-89

Product status

Any version
affected

References

bst.cloudapps.cisco.com/bugsearch/bug/CSCvk27179

cve.org (CVE-2018-0404)

nvd.nist.gov (CVE-2018-0404)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2018-0404

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.