March 25, 2022 · Applied Cybernetics Group
CVE-2018-0125 — Cisco VPN Routers
Cisco VPN Routers Remote Code Execution Vulnerability
- Added to KEV
2022-03-25- Federal due date
2022-04-15- Vendor
- Cisco
- Product
- VPN Routers
- EPSS
- 96.7th percentile (score 0.295, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2018-0125
CISA short description
A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
Required action
Apply updates per vendor instructions.