cisco-sa-20191120-sbr-rv-infodis
Cisco Small Business Routers RV016, RV042, RV042G, and RV082 Information Disclosure Vulnerability
Medium · Updated · Cisco
1 product with CSAF evidence
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attacker to view information displayed in the web-based management interface. The vulnerability is due to improper authorization of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to view information displayed in the web-based management interface without authentication. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.