peter bassill · operator
$ cve CVE-2014-0683 JSON

CVE-2014-0683 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 10.6% (pctl 96)

Patch early

A public exploit exists.

Description

The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earlier, and CVR100W router with firmware 1.0.1.19 and earlier does not prevent replaying of modified authentication requests, which allows remote attackers to obtain administrative access by leveraging the ability to intercept requests, aka Bug IDs CSCul94527, CSCum86264, and CSCum86275.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS10.63% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-255
On CISA KEVno
Public exploityes
Published2014-03-06
Last modified2026-06-17

Affected (6)

VendorProduct
ciscocvr100w
ciscocvr100w firmware
ciscorv110w
ciscorv110w firmware
ciscorv215w
ciscorv215w firmware

Public exploits

SourceTitleDate
exploit-dbCisco RV110W - Password Disclosure / Command Execution2018-12-14

References

→ the Explorer  ·  watch your stack  ·  NVD