{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T11:02:32Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"cisco-sa-20060712-crws","slug":"cisco-sa-20060712-crws","vendor":"Cisco","title":"Cisco Router Web Setup Ships with Insecure Default IOS Configuration","summary":"The default Cisco IOS configuration shipped with the Cisco Router Web Setup (CRWS) application allows the execution of commands at privilege level 15 through the Cisco IOS HTTP (Hypertext Transfer Protocol) server web interface without requiring authentication credentials. Privilege level 15 is the highest privilege level on Cisco IOS�� devices. Fixed versions of the CRWS application have been modified by Cisco to provide a more secure default IOS configuration and additional functionality with regards to the Cisco IOS HTTP server web interface. This issue does not require a Cisco IOS software upgrade or a CRWS software upgrade. Customers who decide to upgrade to a fixed version of CRWS and deploy the new default IOS configuration will not need to deploy the suggested workarounds. Customers who elect NOT to upgrade to a fixed CRWS version, or customers upgrading to a fixed CRWS version who keep their existing configuration should implement the workarounds identified in this advisory. Additional information on the new default IOS configuration shipped with the CRWS application is available in the Details section of this advisory. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20060712-crws.","severity":"NA","published_at":"2006-07-12T23:00:00Z","updated_at":"2006-07-12T23:00:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20060712-crws","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/cisco-sa-20060712-crws/csaf/cisco-sa-20060712-crws.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0},"cves":[{"id":"CVE-2006-3595","kev":false}],"public_evidence":[{"product":{"name":"Cisco Router Web Setup Tool","slug":"cisco-router-web-setup-tool","vendor":"Cisco"},"cve":{"id":"CVE-2006-3595"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T04:34:31Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Router Web Setup Tool","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"published_at":"2006-07-12T23:00:00Z","updated_at":"2006-07-12T23:00:00Z","advisory_updated_at":"2006-07-12T23:00:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20060712-crws","row_display_order":1}]}