Vulnerabilities > Cisco > Application Extension Platform > 1.5.1.13

DATE CVE VULNERABILITY TITLE RISK
2021-11-04 CVE-2021-40120 OS Command Injection vulnerability in Cisco Application Extension Platform and IOS XR
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system and execute them using root-level privileges.
network
low complexity
cisco CWE-78
7.2