CVE-2012-0365: Cisco Small Business SRP520-U Series Firmware
High severity, CVSS 9.0. EPSS: 2.8% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the Local TFTP file-upload application on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to upload software to arbitrary directories via unspecified vectors, aka Bug ID CSCtw56009.
Affected products
- Cisco Small Business SRP520-U Series Firmware: version 1.1.0 only
- Cisco Small Business SRP520 Series Firmware: up to and including 1.01.24; version 1.01.01 only; version 1.01.09 only; version 1.01.11 only; version 1.01.19 only; version 1.01.23 only
- Cisco Small Business SRP521W
- Cisco Small Business SRP521W-U
- Cisco Small Business SRP526W
- Cisco Small Business SRP526W-U
- Cisco Small Business SRP527W
- Cisco Small Business SRP527W-U
- Cisco Small Business SRP540 Series Firmware: up to and including 1.02.01; version 1.02.00.023 only
- Cisco Small Business SRP541W
- Cisco Small Business SRP546W
- Cisco Small Business SRP547W
Published 2012-02-25. Last modified 2026-06-16.