← Vulnerability feed

Vulnerability record · CVE-2021-1473 · published 8 April 2021

CVE-2021-1473: Cisco Small Business RV Series Routers web interface auth bypass and command injection

Cisco · Rv340 Firmware

The web-based management interface of Cisco Small Business RV340, RV340W, RV345 and RV345P routers contains multiple flaws, including an OS command injection and a memory buffer overflow. A remote, unauthenticated attacker can bypass authentication, upload files and execute arbitrary commands on the device.

9.8 CVSS 3.1 Critical EPSS 64% · top 0.8% CWE-119 · Memory buffer overflowCWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 7.5
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction required, and public exploit code make this a top-priority patch for exposed RV Series routers.

What it is

The web-based management interface of Cisco Small Business RV340, RV340W, RV345 and RV345P routers contains multiple flaws, including an OS command injection and a memory buffer overflow. A remote, unauthenticated attacker can bypass authentication, upload files and execute arbitrary commands on the device.

Impact

An attacker gains the ability to run arbitrary commands with the router's privileges and to bypass authentication, effectively taking full control of the device and its network position.

Attack surface

Reachable over the network through the web-based management interface (CVSS vector AV:N/PR:N/UI:N), so no credentials or user interaction are required. The advisory does not state whether the interface must be internet-exposed or only reachable from the LAN.

Exploitation

Not listed in CISA KEV, but EPSS is 0.64161 (99.19th percentile) and public references are tagged Exploit, indicating working exploit code is publicly available. No ransomware association is documented.

What to do

  • Apply the Cisco firmware updates referenced in the vendor advisory cisco-sa-sb-rv-bypass-inject-Rbhgvfdx as the first action.
  • Disable or restrict remote management on the WAN interface and limit web UI access to trusted management networks.
  • Place the router behind a firewall or management VLAN so the web interface is not reachable from untrusted networks.
  • Replace end-of-support RV Series units where no fixed firmware is available.
  • Monitor vendor advisories for updated fixed-version guidance, since this record does not list affected or fixed versions.

Detection

  • Review web server and management interface logs for unauthenticated POST requests or file upload attempts to the router UI.
  • Alert on unexpected outbound connections or new listening services originating from RV Series routers.
  • Monitor for command-injection patterns and abnormal child processes on the device where logging permits.
  • Track authentication bypass indicators such as admin sessions or configuration changes without a preceding successful login.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-1473 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed9.8CVE-2022-20700Cisco Small Business RV Series Routers stack-based buffer overflowCVE-2022-20700 is a stack-based buffer overflow and out-of-bounds write in Cisco Small Business RV160, RV260, RV340 and RV345 Series Routers. The adv…KEVEPSS 5.7%analysed9.8CVE-2022-20699Cisco Small Business RV Series Routers Stack Buffer OverflowCisco Small Business RV160, RV260, RV340 and RV345 series routers contain a stack-based buffer overflow (CWE-121) that can be triggered remotely with…KEVEPSS 72%analysed8.0CVE-2022-20703Cisco Small Business RV Series Routers stack-based buffer overflowCVE-2022-20703 covers multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340 and RV345 Series Routers, including a stack-based buffer o…KEVEPSS 9.2%analysed8.0CVE-2022-20708Cisco Small Business RV Series Routers buffer overflow and command injectionCisco Small Business RV160, RV260, RV340 and RV345 Series Routers contain stack-based buffer overflow and OS command injection flaws. Successful expl…KEVEPSS 15%analysed7.8CVE-2022-20701Cisco Small Business RV Series Routers Stack Buffer OverflowCVE-2022-20701 is a stack-based buffer overflow (CWE-121) and out-of-bounds write (CWE-787) in Cisco Small Business RV160, RV260, RV340, and RV345 Se…KEVEPSS 9.7%analysed10.0CVE-2022-20827Cisco rv160 firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to exe…EPSS 1.9%9.8CVE-2023-20073Cisco RV340/RV345 routers allow unauthenticated arbitrary file uploadThe web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers fails to enforce authorization on file uplo…EPSS 90%analysed

Source: NIST National Vulnerability Database (record CVE-2021-1473), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.