CVE-2017-3882 Details
Description
A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote code execution could occur with root privileges. The vulnerability is due to incomplete range checks of the UPnP input data, which could result in a buffer overflow. An attacker could exploit this vulnerability by sending a malicious request to the UPnP listening port of the targeted device. An exploit could allow the attacker to cause the device to reload or potentially execute arbitrary code with root privileges. This vulnerability affects all firmware releases of the Cisco CVR100W Wireless-N VPN Router prior to Firmware Release 1.0.1.22. Cisco Bug IDs: CSCuz72642.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170503-cvr100w1 | CVE | Vendor Advisory |
| http://www.securityfocus.com/bid/98287 | CVE | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038391 | CVE | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170503-cvr100w1 | [email protected] | Vendor Advisory |
| http://www.securityfocus.com/bid/98287 | [email protected] | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038391 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco small business rv router firmware | 1.0.0.30 1.0.1.9 1.0.1.19 1.0.2.6 1.0.3.10 1.0.4.10 1.0.4.14 1.0.5.4 1.0.5.4(gd) 1.0.5.5 1.0.5.6 1.0.5.8 1.0.6.6 1.0.39 |
CPE
Remediation
| |
| cisco small business rv router firmware 1.0 | 0.2 |
CPE
Remediation
| |
| cisco rv042 | All versions |
CPE
Remediation
| |
| cisco rv042g | All versions |
CPE
Remediation
| |
| cisco rv082 | All versions |
CPE
Remediation
| |
| cisco rv110w | All versions |
CPE
Remediation
| |
| cisco rv130 | All versions |
CPE
Remediation
| |
| cisco rv130 wf | All versions |
CPE
Remediation
| |
| cisco rv130w | All versions |
CPE
Remediation
| |
| cisco rv130w wf | All versions |
CPE
Remediation
| |
| cisco rv132w | All versions |
CPE
Remediation
| |
| cisco rv134w | All versions |
CPE
Remediation
| |
| cisco rv215w | All versions |
CPE
Remediation
| |
| cisco rv320 | All versions |
CPE
Remediation
| |
| cisco rv320 wf | All versions |
CPE
Remediation
| |
| cisco rv325 | All versions |
CPE
Remediation
| |
| cisco rv325 wf | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Jul 11, 2017 | CVE Modified | [email protected] |
| May 24, 2017 | Initial Analysis | [email protected] |
| May 18, 2017 | CVE Modified | [email protected] |