CVE-2018-0405
A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to conduct a directory path traversal attack on a targeted device. The issue is due to improper sanitization of user-supplied input in HTTP request parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location.
Published:Oct 5, 2018
Last Modified:Nov 26, 2024
EPS:Oct 5, 2018
EPSS Score:0.03725
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Cisco
Product
Rv180w
Cisco
Rv180w
Vendor
Cisco
Product
Rv180w Firmware
Cisco
Rv180w Firmware
Vendor
Cisco
Product
Rv220w
Cisco
Rv220w
Vendor
Cisco
Product
Rv220w Firmware
Cisco
Rv220w Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
