Vulnerability record · CVE-2018-0127 · published 8 February 2018
CVE-2018-0127: Cisco RV132W and RV134W router web interface missing authentication exposes admin password
Cisco · Rv132w Firmware
The web interface of Cisco RV132W and RV134W VPN routers fails to require authentication for certain pages that hold device configuration data. An unauthenticated remote attacker can request those pages and read configuration parameters, including the administrator password. This is a missing-authentication information exposure flaw in internet-facing small-business routers.
Description
A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to the absence of user authentication requirements for certain pages that are part of the web interface and contain confidential information for an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device and examining the HTTP response to the request. A successful exploit could allow the attacker to view configuration parameters, including the administrator password, for the affected device. Cisco Bug IDs: CSCvg92739, CSCvh60172.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and direct disclosure of the administrator password, though no KEV listing or documented exploit exists.
What it is
The web interface of Cisco RV132W and RV134W VPN routers fails to require authentication for certain pages that hold device configuration data. An unauthenticated remote attacker can request those pages and read configuration parameters, including the administrator password. This is a missing-authentication information exposure flaw in internet-facing small-business routers.
Impact
An attacker gains read access to device configuration, including the administrator password, enabling full administrative takeover of the router and any traffic or VPN credentials it handles.
Attack surface
Reachable over the network through the router web interface via a crafted HTTP request; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is very high (0.775, 99.5th percentile), indicating strong likelihood of exploitation activity.
What to do
- Apply the Cisco firmware fix for RV132W and RV134W per the vendor advisory cisco-sa-20180207-rv13x_2.
- Disable remote management of the web interface and restrict administrative access to trusted internal networks.
- Change the administrator password after patching, since it may already have been disclosed.
- Place affected routers behind a firewall or VPN and block inbound HTTP/HTTPS to the management interface from the internet.
- Replace end-of-support units that no longer receive firmware updates.
Detection
- Monitor router and perimeter logs for unauthenticated HTTP requests to configuration or password pages on RV132W/RV134W management interfaces.
- Alert on inbound connections to the router web interface from external or unexpected source addresses.
- Audit router configuration and admin credentials for signs of unauthorized change or reuse.
- Track vendor advisories and asset inventory for unpatched RV132W/RV134W devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/102969 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040345 | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-rv13x_2 | Vendor Advisory |
| http://www.securityfocus.com/bid/102969 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040345 | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-rv13x_2 | Vendor Advisory |
Track CVE-2018-0127 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0127), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.