Cisco patches critical vulnerabilities in SME routers

By

Arbitrary code and command execution and other flaws fixed.

Users of Cisco's RV series of small to medium-sized business routers are advised to patch their equipment urgently to fix multiple critical vulnerabilities.

Cisco patches critical vulnerabilities in SME routers

The vulnerabitilies allow attackers to run arbitrary code and commands on the routers, as well bypass user authentication and cause denial-of-service scenarios.

Attackers can also elevate user privileges and fetch and run unsigned software by exploiting the vulnerabilities, Cisco said.

Three of the vulnerabilities are rated at the full 10.0 on the Common Vulnerabilities Scoring System (CVSS).

Cisco said the following routers need patching:

  • RV160 VPN 
  • RV160W Wireless-AC VPN
  • RV260 VPN
  • RV260P VPN routers with PoE
  • RV260W Wireless-AC VPN
  • RV340 Dual WAN Gigabit VPN
  • RV340W Dual WAN Gigabit Wireless-AC VPN
  • RV345 Dual WAN Gigabit VPN
  • RV345P Dual WAN Gigabit POE VPN

In addition, the RV340, RV340W, RV345 and RV345P devices also contain some of the vulnerabilities in Cisco's security advisory, and need patching.

No workarounds are available for the vulnerabilities, Cisco said.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Cloudflare makes changes to avoid repeat of 1.1.1.1 DNS outage

Cloudflare makes changes to avoid repeat of 1.1.1.1 DNS outage

NSW Police seeks lead for 'critical' network uplift

NSW Police seeks lead for 'critical' network uplift

Tanner reveals interim data centre panel

Tanner reveals interim data centre panel

The Asus ZenWiFi Pro XT12 delivers fast, reliable wireless networking for SMBs

The Asus ZenWiFi Pro XT12 delivers fast, reliable wireless networking for SMBs

Log In

  |  Forgot your password?