CVE-2016-1395
9.8
CRITICAL · CVSS 3.0 · EPSS 4.8% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to execute arbitrary code as root via a crafted HTTP request, aka Bug ID CSCux82428.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.81% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-06-19 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| cisco | rv110w wireless-n vpn firewall |
| cisco | rv110w wireless-n vpn firewall firmware |
| cisco | rv130w wireless-n multifunction vpn router |
| cisco | rv130w wireless-n multifunction vpn router firmware |
| cisco | rv215w wireless-n vpn router |
| cisco | rv215w wireless-n vpn router firmware |
References
→ the Explorer · watch your stack · NVD