We have a Cisco RV-042 Small Business router and our PCI scans flagged it as being vulnerable to CVE-2014-0224 (CCS Injection/Man-in-the-Middle). It appears to be another OpenSSL vulnerability.
We have the latest firmware (Apr 2014) installed, but can't wait around forever for Cisco to fix. So I have a few questions:
1) There is an option to disable SSL on the router. Does anyone know what the effects of this are? Does this only impact the web admin, or would VPN also be impacted?
2) Cisco seems to have fallen over a cliff on support of their products. What alternatives have you had success with that provide regular firmware updates (especially for PCI/Security related issues) and good support for their products?
I propose for now that you:
In the long term you should probably find another router, the software for which is better supported by its manufacturer. (I'm not going to make any recommendations, though.)