← Vulnerability feed

Vulnerability record · CVE-2018-0127 · published 8 February 2018

CVE-2018-0127: Cisco RV132W and RV134W router web interface missing authentication exposes admin password

Cisco · Rv132w Firmware

The web interface of Cisco RV132W and RV134W VPN routers fails to require authentication for certain pages that hold device configuration data. An unauthenticated remote attacker can request those pages and read configuration parameters, including the administrator password. This is a missing-authentication information exposure flaw in internet-facing small-business routers.

9.8 CVSS 3.1 Critical EPSS 77% · top 0.5% CWE-200 · Information exposureCWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 5.0
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to the absence of user authentication requirements for certain pages that are part of the web interface and contain confidential information for an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device and examining the HTTP response to the request. A successful exploit could allow the attacker to view configuration parameters, including the administrator password, for the affected device. Cisco Bug IDs: CSCvg92739, CSCvh60172.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required and direct disclosure of the administrator password, though no KEV listing or documented exploit exists.

What it is

The web interface of Cisco RV132W and RV134W VPN routers fails to require authentication for certain pages that hold device configuration data. An unauthenticated remote attacker can request those pages and read configuration parameters, including the administrator password. This is a missing-authentication information exposure flaw in internet-facing small-business routers.

Impact

An attacker gains read access to device configuration, including the administrator password, enabling full administrative takeover of the router and any traffic or VPN credentials it handles.

Attack surface

Reachable over the network through the router web interface via a crafted HTTP request; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is very high (0.775, 99.5th percentile), indicating strong likelihood of exploitation activity.

What to do

  • Apply the Cisco firmware fix for RV132W and RV134W per the vendor advisory cisco-sa-20180207-rv13x_2.
  • Disable remote management of the web interface and restrict administrative access to trusted internal networks.
  • Change the administrator password after patching, since it may already have been disclosed.
  • Place affected routers behind a firewall or VPN and block inbound HTTP/HTTPS to the management interface from the internet.
  • Replace end-of-support units that no longer receive firmware updates.

Detection

  • Monitor router and perimeter logs for unauthenticated HTTP requests to configuration or password pages on RV132W/RV134W management interfaces.
  • Alert on inbound connections to the router web interface from external or unexpected source addresses.
  • Audit router configuration and admin credentials for signs of unauthorized change or reuse.
  • Track vendor advisories and asset inventory for unpatched RV132W/RV134W devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0127 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0125Cisco RV132W/RV134W routers unauthenticated remote code execution via HTTP input validation flawThe web interface of Cisco RV132W and RV134W VPN routers fails to properly validate user-controlled input in HTTP requests, allowing crafted requests…KEVEPSS 55%analysed8.8CVE-2021-1309Cisco rv132w firmware memory buffer overflow vulnerabilityMultiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthentica…EPSS 0.52%7.4CVE-2021-1251Cisco rv132w firmware memory buffer overflow vulnerabilityMultiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthentica…EPSS 0.43%7.4CVE-2021-1308Cisco rv132w firmware memory buffer overflow vulnerabilityMultiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthentica…EPSS 0.43%7.2CVE-2021-1287Cisco rv132w firmware stack-based buffer overflow vulnerabilityA vulnerability in the web-based management interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers co…EPSS 2.2%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed7.5CVE-2026-20133Cisco Catalyst SD-WAN Manager insufficient file system restrictions expose dataCisco Catalyst SD-WAN Software has insufficient file system restrictions that let an attacker read sensitive files on the underlying operating system…KEVEPSS 32%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2018-0127), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.