Vulnerability record · CVE-2021-1473 · published 8 April 2021
CVE-2021-1473: Cisco Small Business RV Series Routers web interface auth bypass and command injection
Cisco · Rv340 Firmware
The web-based management interface of Cisco Small Business RV340, RV340W, RV345 and RV345P routers contains multiple flaws, including an OS command injection and a memory buffer overflow. A remote, unauthenticated attacker can bypass authentication, upload files and execute arbitrary commands on the device.
Description
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction required, and public exploit code make this a top-priority patch for exposed RV Series routers.
What it is
The web-based management interface of Cisco Small Business RV340, RV340W, RV345 and RV345P routers contains multiple flaws, including an OS command injection and a memory buffer overflow. A remote, unauthenticated attacker can bypass authentication, upload files and execute arbitrary commands on the device.
Impact
An attacker gains the ability to run arbitrary commands with the router's privileges and to bypass authentication, effectively taking full control of the device and its network position.
Attack surface
Reachable over the network through the web-based management interface (CVSS vector AV:N/PR:N/UI:N), so no credentials or user interaction are required. The advisory does not state whether the interface must be internet-exposed or only reachable from the LAN.
Exploitation
Not listed in CISA KEV, but EPSS is 0.64161 (99.19th percentile) and public references are tagged Exploit, indicating working exploit code is publicly available. No ransomware association is documented.
What to do
- Apply the Cisco firmware updates referenced in the vendor advisory cisco-sa-sb-rv-bypass-inject-Rbhgvfdx as the first action.
- Disable or restrict remote management on the WAN interface and limit web UI access to trusted management networks.
- Place the router behind a firewall or management VLAN so the web interface is not reachable from untrusted networks.
- Replace end-of-support RV Series units where no fixed firmware is available.
- Monitor vendor advisories for updated fixed-version guidance, since this record does not list affected or fixed versions.
Detection
- Review web server and management interface logs for unauthenticated POST requests or file upload attempts to the router UI.
- Alert on unexpected outbound connections or new listening services originating from RV Series routers.
- Monitor for command-injection patterns and abnormal child processes on the device where logging permits.
- Track authentication bypass indicators such as admin sessions or configuration changes without a preceding successful login.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162238/Cisco-RV-Authentication-Bypass-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2021/Apr/39 | Mailing ListThird Party Advisory |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-bypass-inject-Rbhgvfdx | Vendor Advisory |
| http://packetstormsecurity.com/files/162238/Cisco-RV-Authentication-Bypass-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2021/Apr/39 | Mailing ListThird Party Advisory |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-bypass-inject-Rbhgvfdx | Vendor Advisory |
Track CVE-2021-1473 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-1473), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.