← Vulnerability feed

Vulnerability record · CVE-2021-1542 · published 16 June 2021

CVE-2021-1542: Cisco sf220-24 firmware improper authentication vulnerability

Cisco · Sf220 24 Firmware

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.

8.1 CVSS 3.1 High EPSS 1.4% · top 28.9% CWE-287 · Improper authentication
8.1CVSS 3.1 base score, v2 9.3
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-1542 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-1913Cisco sf-220-24 firmware memory buffer overflow vulnerabilityMultiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote att…EPSS 26%9.1CVE-2019-1912Cisco sf-220-24 firmware improper authorization vulnerabilityA vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to …EPSS 17%7.2CVE-2021-1541Cisco sf220-24 firmware improper authentication vulnerabilityMultiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the fo…EPSS 8.8%7.2CVE-2019-1914Cisco sf-220-24 firmware improper input validation vulnerabilityA vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to pe…EPSS 25%6.1CVE-2021-1571Cisco sf220-24 firmware improper authentication vulnerabilityMultiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the fo…EPSS 9.7%6.1CVE-2021-1543Cisco sf220-24 firmware improper authentication vulnerabilityMultiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the fo…EPSS 9.3%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed

Source: NIST National Vulnerability Database (record CVE-2021-1542), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.