CVE-2021-1295
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to remotely execute arbitrary code on the device.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 1.87%
- CWE
- CWE-472
- Published
- 2021-02-04
- Last modified
- 2026-03-13
Affected products
- Cisco Cisco Small Business RV Series Router Firmware
Weakness type
Related vulnerabilities
- CVE-2024-25153 — Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114
- CVE-2025-35939 — Craft CMS stores user-provided content in session files
- CVE-2026-14387 — Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sand
- CVE-2026-13796 — Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the
- CVE-2026-11088 — Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rend
- CVE-2021-1293 — Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
- CVE-2021-1294 — Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
- CVE-2021-1292 — Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities