← Vulnerability feed

Vulnerability record · CVE-2018-0125 · published 8 February 2018

CVE-2018-0125: Cisco RV132W/RV134W routers unauthenticated remote code execution via HTTP input validation flaw

Cisco · Rv132w Firmware

The web interface of Cisco RV132W and RV134W VPN routers fails to properly validate user-controlled input in HTTP requests, allowing crafted requests to reach vulnerable code paths. A remote, unauthenticated attacker can exploit this to run arbitrary code as root or force the device to reload. Because the flaw is reachable without credentials and yields root-level control, it is a severe risk to any exposed router.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 EPSS 55% · top 1.0% CWE-20 · Improper input validation
9.8CVSS 3.1 base score, v2 10.0
55%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to an incomplete input validation on user-controlled input in an HTTP request to the targeted device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to execute arbitrary code as the root user and gain full control of the affected system or cause it to reload, resulting in a DoS condition. This vulnerability is fixed in firmware version 1.0.1.11 for the following Cisco products: RV132W ADSL2+ Wireless-N VPN Router and RV134W VDSL2 Wireless-AC VPN Router. Cisco Bug IDs: CSCvg92737, CSCvh60170.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution as root with a CVSS of 9.8 and confirmed exploitation in CISA KEV makes this an urgent patching priority.

What it is

The web interface of Cisco RV132W and RV134W VPN routers fails to properly validate user-controlled input in HTTP requests, allowing crafted requests to reach vulnerable code paths. A remote, unauthenticated attacker can exploit this to run arbitrary code as root or force the device to reload. Because the flaw is reachable without credentials and yields root-level control, it is a severe risk to any exposed router.

Impact

An attacker gains full control of the affected router, including the ability to issue commands with root privileges, and can alternatively crash or reload the device to cause a denial of service.

Attack surface

The flaw is reached over the network through the device web interface via a crafted HTTP request. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CVE-2018-0125 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), indicating exploitation in the wild, and EPSS gives a 30-day probability of roughly 0.55 (98.9th percentile). No ransomware campaign use is documented in the record.

What to do

  • Upgrade RV132W and RV134W firmware to version 1.0.1.11 or later as directed by Cisco.
  • Remove or restrict internet-facing management access to the router web interface; place management behind a VPN or trusted network.
  • Disable remote management/HTTP access from untrusted networks where the feature is not required.
  • Monitor vendor advisories and CISA KEV guidance for this CVE and apply the required action.
  • If patching is not immediately possible, isolate affected routers on segmented networks and limit reachable services.

Detection

  • Inspect HTTP request logs and network traffic to the router web interface for malformed or unusually long input parameters.
  • Alert on unexpected device reloads or reboots that could indicate a DoS attempt.
  • Monitor for anomalous outbound connections or command execution behavior originating from the router.
  • Check firmware versions of RV132W/RV134W devices against the fixed 1.0.1.11 release.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-0125 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Cisco VPN Routers Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0125 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0127Cisco RV132W and RV134W router web interface missing authentication exposes admin passwordThe web interface of Cisco RV132W and RV134W VPN routers fails to require authentication for certain pages that hold device configuration data. An un…EPSS 77%analysed8.8CVE-2021-1309Cisco rv132w firmware memory buffer overflow vulnerabilityMultiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthentica…EPSS 0.52%7.4CVE-2021-1251Cisco rv132w firmware memory buffer overflow vulnerabilityMultiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthentica…EPSS 0.43%7.4CVE-2021-1308Cisco rv132w firmware memory buffer overflow vulnerabilityMultiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthentica…EPSS 0.43%7.2CVE-2021-1287Cisco rv132w firmware stack-based buffer overflow vulnerabilityA vulnerability in the web-based management interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers co…EPSS 2.2%9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2018-0125), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.