Four Cisco RV series routers intended for small businesses have been found vulnerable to attacks that could allow the execution of arbitrary commands and the uploading of files to any location on the device
The affected devices are the following: Cisco RV120W Wireless-N VPN Firewall, Cisco RV180 VPN Router, Cisco RV180W Wireless-N Multifunction VPN Router, and Cisco RV220W Wireless Network Security Firewall.
Cisco made a detailed announcement on Wednesday about the three vulnerabilities in total that the above products have and released firmware updates for all of them, with the exception of the RV220W, for which a patch is expected at the end of the month.
One of the vulnerabilities identified by the company allows a potential attacker to remotely execute arbitrary commands with elevated administrative (root) privileges by making a corresponding HTTP request to the vulnerable device. The flaw can be exploited provided that the attacker is authenticated.
Labeled CVE-2014-2177, the flaw is in the routers' network diagnostics administration pages and results from an error in the validation process of user-provided data. Another flaw, CVE-2014-2178, included in the most recent updates, created the possibility of conducting a cross-site request forgery (CSRF) attack, remotely, without the attacker's authentication. The third vulnerability (CVE-2014-2179) found in Cisco RV series routers is located in the way uploaded files are executed. The vulnerability allows an attacker to remotely and without authentication place a file anywhere on the device.
Cisco has released update 1.0.4.14 for the RV180 and RV180W and 1.0.5.9 for the RV120W. If you are unable to update your device software immediately, the company is offering a workaround to temporarily mitigate the risks until the update is installed.
Cisco recommends disabling remote management for devices so that an attacker outside the network is unable to connect to the router. However, if management is done over the WAN, this action is not required. Another option is to limit remote management rights to specific IP addresses.

