Lucene search

K
zdiTrichimtrich and nyancat0131ZDI-22-418
HistoryFeb 22, 2022 - 12:00 a.m.

(Pwn2Own) Cisco RV340 Plug and Play Command Injection Remote Code Execution Vulnerability

2022-02-2200:00:00
trichimtrich and nyancat0131
www.zerodayinitiative.com
14
cisco rv340
plug and play
command injection
remote code execution
authentication bypass
firmware update
system call
root access

EPSS

0.023

Percentile

89.8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco RV340 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of firmware updates. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.

EPSS

0.023

Percentile

89.8%