CVE Feed

    Dashboard / CVE / CVE-2017-3882

    CVE-2017-3882

    A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote code execution could occur with root privileges. The vulnerability is due to incomplete range checks of the UPnP input data, which could result in a buffer overflow. An attacker could exploit this vulnerability by sending a malicious request to the UPnP listening port of the targeted device. An exploit could allow the attacker to cause the device to reload or potentially execute arbitrary code with root privileges. This vulnerability affects all firmware releases of the Cisco CVR100W Wireless-N VPN Router prior to Firmware Release 1.0.1.22. Cisco Bug IDs: CSCuz72642.

    Published:May 16, 2017
    Last Modified:Apr 20, 2025
    EPS:May 16, 2017
    EPSS Score:0.00786
    CVSS Score:9.6

    Affected Products

    Vendor
    Cisco
    Product
    Rv042
    Vendor
    Cisco
    Product
    Rv042g
    Vendor
    Cisco
    Product
    Rv082
    Vendor
    Cisco
    Product
    Rv110w
    Vendor
    Cisco
    Product
    Rv130
    Vendor
    Cisco
    Product
    Rv130 Wf
    Vendor
    Cisco
    Product
    Rv130w
    Vendor
    Cisco
    Product
    Rv130w Wf
    Vendor
    Cisco
    Product
    Rv132w
    Vendor
    Cisco
    Product
    Rv134w
    Vendor
    Cisco
    Product
    Rv215w
    Vendor
    Cisco
    Product
    Rv320
    Vendor
    Cisco
    Product
    Rv320 Wf
    Vendor
    Cisco
    Product
    Rv325
    Vendor
    Cisco
    Product
    Rv325 Wf
    Vendor
    Cisco
    Product
    Small Business Rv Router Firmware
    Vendor
    Cisco
    Product
    Small Business Rv Router Firmware 1.0

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High