Vulnerability record · CVE-2018-0125 · published 8 February 2018
CVE-2018-0125: Cisco RV132W/RV134W routers unauthenticated remote code execution via HTTP input validation flaw
Cisco · Rv132w Firmware
The web interface of Cisco RV132W and RV134W VPN routers fails to properly validate user-controlled input in HTTP requests, allowing crafted requests to reach vulnerable code paths. A remote, unauthenticated attacker can exploit this to run arbitrary code as root or force the device to reload. Because the flaw is reachable without credentials and yields root-level control, it is a severe risk to any exposed router.
Description
A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to an incomplete input validation on user-controlled input in an HTTP request to the targeted device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to execute arbitrary code as the root user and gain full control of the affected system or cause it to reload, resulting in a DoS condition. This vulnerability is fixed in firmware version 1.0.1.11 for the following Cisco products: RV132W ADSL2+ Wireless-N VPN Router and RV134W VDSL2 Wireless-AC VPN Router. Cisco Bug IDs: CSCvg92737, CSCvh60170.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution as root with a CVSS of 9.8 and confirmed exploitation in CISA KEV makes this an urgent patching priority.
What it is
The web interface of Cisco RV132W and RV134W VPN routers fails to properly validate user-controlled input in HTTP requests, allowing crafted requests to reach vulnerable code paths. A remote, unauthenticated attacker can exploit this to run arbitrary code as root or force the device to reload. Because the flaw is reachable without credentials and yields root-level control, it is a severe risk to any exposed router.
Impact
An attacker gains full control of the affected router, including the ability to issue commands with root privileges, and can alternatively crash or reload the device to cause a denial of service.
Attack surface
The flaw is reached over the network through the device web interface via a crafted HTTP request. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CVE-2018-0125 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), indicating exploitation in the wild, and EPSS gives a 30-day probability of roughly 0.55 (98.9th percentile). No ransomware campaign use is documented in the record.
What to do
- Upgrade RV132W and RV134W firmware to version 1.0.1.11 or later as directed by Cisco.
- Remove or restrict internet-facing management access to the router web interface; place management behind a VPN or trusted network.
- Disable remote management/HTTP access from untrusted networks where the feature is not required.
- Monitor vendor advisories and CISA KEV guidance for this CVE and apply the required action.
- If patching is not immediately possible, isolate affected routers on segmented networks and limit reachable services.
Detection
- Inspect HTTP request logs and network traffic to the router web interface for malformed or unusually long input parameters.
- Alert on unexpected device reloads or reboots that could indicate a DoS attempt.
- Monitor for anomalous outbound connections or command execution behavior originating from the router.
- Check firmware versions of RV132W/RV134W devices against the fixed 1.0.1.11 release.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0125 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Cisco VPN Routers Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103140 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040336 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-rv13x | Broken LinkVendor Advisory |
| http://www.securityfocus.com/bid/103140 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040336 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-rv13x | Broken LinkVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0125 | US Government Resource |
Track CVE-2018-0125 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0125), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.