CVE-2024-20521

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 787
CWE ID 121

Summary

CVE-2024-20521 is a vulnerability affecting the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers. This issue allows authenticated, Administrator-level attackers to execute arbitrary code as the root user, exploiting it requires valid Administrator credentials. The root cause is improper input validation in the web-based management interface, enabling attackers to send crafted HTTP requests that could lead to code execution on the underlying operating system. If exploited, an attacker could gain complete control over the affected device.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Rv320 Firmware
  • Cisco Rv325 Firmware

Affected Vendors

  • Cisco