Three models of Cisco wireless VPN firewalls and routers from the small business RV series contain a critical unpatched vulnerability. The vulnerability is located in the Web-based management interface of the Cisco RV110W Wireless-N VPN Firewall and RV130W VPN-N Multifunction VPN Router. The company plans to release firmware updates that will address this flaw on affected models sometime in the third quarter of 2016. No patches are yet available, but the company also warned of a medium-severity, cross-site scripting (XSS) flaw.”]