CVE-2015-6396

The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:cisco:rv110w_wireless-n_vpn_firewall_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:rv110w_wireless-n_vpn_firewall:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:rv130w_wireless-n_multifunction_vpn_router:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:rv215w_wireless-n_vpn_router:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-08-08 00:59

Updated : 2024-02-04 18:53


NVD link : CVE-2015-6396

Mitre link : CVE-2015-6396

CVE.ORG link : CVE-2015-6396


JSON object : View

Products Affected

cisco

  • rv130w_wireless-n_multifunction_vpn_router
  • rv110w_wireless-n_vpn_firewall
  • rv130w_wireless-n_multifunction_vpn_router_firmware
  • rv215w_wireless-n_vpn_router
  • rv110w_wireless-n_vpn_firewall_firmware
  • rv215w_wireless-n_vpn_router_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')