Security News > 2021 > February > Cisco Patches Critical Vulnerabilities in Small Business Routers, SD-WAN
![Cisco Patches Critical Vulnerabilities in Small Business Routers, SD-WAN](/static/build/img/news/alt/managed-security-medium.jpg)
Cisco this week released software updates to address multiple vulnerabilities across its product portfolio, including critical severity bugs in several small business VPN routers and SD-WAN products.
The company warned that the web-based management interface of small business RV160, RV160W, RV260, RV260P, and RV260W VPN routers is affected by seven severe vulnerabilities that could be abused by unauthenticated, remote attackers to execute arbitrary code as root.
The Cisco RV016, RV042, RV042G, and RV082 routers won't receive patches, because they have already reached end-of-life status.
Other high risk vulnerabilities that Cisco patched this week affect IOS XR software: one denial of service in the IPv6 protocol handling and two in the ingress packet processing function of IOS XR software, and two image verification bugs and one privilege escalation that affect IOS XR software for the Cisco 8000 series routers and Network Convergence System 540 series routers.
Cisco also released patches for medium severity flaws in Webex, Unified Computing System, IOS XR Software, Managed Services Accelerator, and DNA Center, and announced that it would release software updates to fix multiple bugs in the DNS forwarder implementation of dnsmasq.
Further information on the vulnerabilities Cisco has addressed in its products this week can be found on the company's security portal.
News URL
Related news
- Netgear warns users to patch critical WiFi router vulnerabilities (source)
- Cisco Patches Critical ISE Vulnerabilities Enabling Root CmdExec and PrivEsc (source)
- CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List (source)
- New botnet exploits vulnerabilities in NVRs, TP-Link routers (source)
- Moxa Alerts Users to High-Severity Vulnerabilities in Cellular and Secure Routers (source)
- SAP fixes critical vulnerabilities in NetWeaver application servers (source)
- Critical vulnerabilities remain unresolved due to prioritization gaps (source)
- Critical SimpleHelp vulnerabilities fixed, update your server instances! (source)
- Cisco Fixes Critical Privilege Escalation Flaw in Meeting Management (CVSS 9.9) (source)
- Cisco fixes ClamAV vulnerability with available PoC and critical Meeting Management flaw (source)