LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-20699: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-20699 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary…

CVE-2022-20699 is a stack-based buffer overflow vulnerability affecting Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers. If successfully abused, it can let an attacker execute arbitrary code, elevate privileges, run arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service. For teams running these small-business routers at the edge, the issue matters because compromise of the device can undermine the network boundary itself.

Public detail is limited to the product family and impact classes listed by CISA; exact attack preconditions, exposed interfaces, and fixed releases must be confirmed against the vendor advisory before you act.

How it works

The weakness is recorded as CWE-785 and is described as a stack-based buffer overflow in the Cisco Small Business RV series routers named above. In this class of flaw, input is handled in a way that can overrun a fixed-size stack buffer. When that happens, an attacker who can reach the vulnerable processing path may corrupt control data on the stack.

According to the CISA summary, successful abuse can lead to arbitrary code execution, privilege elevation, arbitrary command execution, bypass of authentication and authorization protections, retrieval and execution of unsigned software, or a denial-of-service condition. The precise network path, whether authentication is required, and the exact input that triggers the overflow are not provided in the given facts; treat any public proof-of-concept claims cautiously and validate behavior only against the official Cisco advisory and your own lab testing.

Am I affected? How to find it in your systems

These devices are typically deployed as small-office or branch internet gateways, VPN endpoints, or simple firewall/router appliances. Inventory every Cisco Small Business RV160, RV260, RV340, and RV345 unit on your network, including units still in staging, lab, or spare pools.

If you cannot determine the exact firmware level, assume the device may be vulnerable until you confirm otherwise with the vendor advisory.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the fixed software image only from Cisco, verify integrity according to Cisco’s guidance, and install it on every affected RV160, RV260, RV340, and RV345 unit during a controlled maintenance window.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to edge routers.

If your data may have been exposed

Actively exploited router vulnerabilities can lead to full network compromise and subsequent data theft, even when ransomware use is not documented for this CVE. If you have evidence of exploitation or cannot rule it out, follow your incident-response process: isolate affected segments, preserve logs and device images, rotate credentials that traversed the device, and assess downstream systems for lateral movement. You can also run a free exposure scan of your email addresses against known breach data sets to check whether credentials or personal data associated with your domain have already appeared in public breach corpora, then force resets and monitoring where matches are found.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Small Business RV160, RV260, RV340, and RV345 Series Routers
WeaknessCWE-785
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities