CVE-2022-20699: critical vulnerability in Cisco Small Business RV Series Router Firmware
Cisco Small Business RV Series Routers Vulnerabilities
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
Cisco Small Business routers (RV160, RV260, RV340, RV345) have critical flaws that let attackers take complete control by running malicious code, bypassing security checks, or crashing the device. These are serious vulnerabilities affecting network equipment used by many businesses.
Multiple stack-based buffer overflows and authentication bypass vulnerabilities in Cisco RV Series routers allow unauthenticated or low-privilege attackers to execute arbitrary code with root privileges, load unsigned firmware, and disable services. Attack vectors include web interface requests and command injection; affected models lack proper input validation and code signing verification.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.