LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-20700: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-20700 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary…

CVE-2022-20700 is a stack-based buffer overflow in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers. Successful abuse can let an attacker execute arbitrary code, elevate privileges, run arbitrary commands, bypass authentication and authorization controls, fetch and run unsigned software, or cause a denial of service. These devices commonly sit at the network edge, so the impact can extend beyond the router itself to the networks and services behind it. Confirm exact fixed releases and any prerequisites against the vendor advisory before acting.

How it works

The weakness is classified as CWE-121 (stack-based buffer overflow). In this class of flaw, input is written into a fixed-size buffer on the stack without adequate bounds checking. Excess data can overwrite adjacent stack memory, which an attacker may try to leverage to alter control flow or corrupt critical state.

According to the CISA summary, an attacker who can reach the vulnerable interface on an affected RV-series router may be able to achieve any of the following outcomes: execute arbitrary code, elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service. Public detail on the precise attack path, required privileges, and whether authentication is needed is limited; treat the vendor advisory as the authoritative source for those mechanics. Do not assume remote unauthenticated exploitation without confirming it in the advisory.

Am I affected? How to find it in your systems

These products are Cisco Small Business routers typically deployed as edge or branch gateways for small and mid-size networks. Inventory every RV160, RV260, RV340, and RV345 series unit, including devices managed by partners or sitting in remote sites.

How to remediate

Patch first. Apply the updates Cisco provides for the affected RV160, RV260, RV340, and RV345 series routers, following the vendor instructions exactly as CISA directs. Confirm the target image and any required intermediate steps in the official advisory before deployment.

If you can't patch immediately

Until the vendor update is installed, reduce exposure with compensating controls appropriate to an edge router buffer-overflow risk.

If your data may have been exposed

Actively exploited edge vulnerabilities can lead to full device compromise and subsequent access to internal networks or credentials. Ransomware use is not documented for this CVE in the provided facts; still treat confirmed compromise seriously. Rotate credentials that may have traversed or been stored on the device, review connected systems for lateral movement, and follow your incident-response process. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Small Business RV160, RV260, RV340, and RV345 Series Routers
WeaknessCWE-121
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities