April 5, 2023, 7:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device and then persuading a user to visit specific web pages that include malicious payloads. A …

attacks business cisco code cross-site cve device exploit http http requests input input validation interface malicious management requests routers rv016 rv042 rv042g rv082 rv320 rv325 script scripting the web validation vulnerabilities web xss

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior Cloud Security Engineer

@ Hearst | Charlotte, NC, United States

Junior Cybersecurity Analyst

@ SavageOne | Johannesburg, GP, South Africa

Information Security Risk Analyst

@ Take-Two Interactive Software, Inc. | Bengaluru, Karnataka, India