Cisco has addressed pre-auth security vulnerabilities affecting many Small Business VPN routers that allow remote attackers to trigger a denial of service condition or execute commands and arbitrary code on vulnerable devices.

The two security flaws identified as CVE-2021-1609 (score 9.8/10) and CVE-2021-1602 (8.2/10) were found in the web-based management interfaces and exist due to improperly validated HTTP requests and insufficient user input validation, respectively.
See also: San Francisco Bay Area: Tech workers return to offices
CVE-2021-1609 affects the routers , while CVE-2021-1602 affects the RV160, RV160W, RV260, RV260P, and RV260W VPN routers.
Both flaws can be exploited remotely without requiring authentication as part of low-sophistication attacks that do not require user interaction.
Attackers could exploit the vulnerabilities by sending malicious HTTP requests to the web-based management interfaces of affected routers.
See also: Vulnerability in Cisco ASA devices: Hackers are actively exploiting it
Remote management has been disabled on all affected routers
Fortunately, as the company explains, the remote management feature is disabled by default on all affected VPN router models.
To find out if remote management is enabled on your devices, you need to open the router's management interface via a local LAN connection and check if the Basic Settings > Remote Management option is enabled.
Cisco has released software to address these vulnerabilities and says there are no workarounds available to remove the attack vectors.
See also: Cisco fails to fix 74 bugs in RV routers that have reached their EOL
To download the patched firmware from the Cisco Software Center, you must click Browse All on Cisco.com and navigate to Downloads Home > Routers > Small Business Routers > Small Business RV Series Routers.
Information source: bleepingcomputer.com
