LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-20701: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-20701 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary…

CVE-2022-20701 is a stack-based buffer overflow vulnerability affecting Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers. If successfully abused, it can let an attacker execute arbitrary code, elevate privileges, run arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service. These devices often sit at the network edge, so compromise can put internal traffic, remote access, and connected systems at risk. Confirm exact impact and fixed releases against the vendor advisory.

How it works

This issue is classed as CWE-121, a stack-based buffer overflow. In this weakness class, software copies more data into a fixed-size stack buffer than the buffer can hold. Excess data can overwrite adjacent stack memory, which may include control information the device uses to decide what code runs next.

An attacker who can reach the vulnerable interface or service on an affected router may send crafted input that triggers the overflow. Depending on how the device handles that input and what memory is overwritten, the result can range from process crash (denial of service) to control-flow hijacking that leads to code execution, privilege elevation, command execution, auth bypass, or loading of unsigned software. Public detail on exact request format, required access level, and reliable exploit steps is limited here; treat any public proof-of-concept claims cautiously and validate behavior only in a controlled lab against the vendor’s description.

Am I affected? How to find it in your systems

These products are small-business and branch routers commonly deployed for internet edge, VPN, and basic firewall duties. Inventory every Cisco RV160, RV260, RV340, and RV345 unit—including devices in remote offices, labs, and forgotten appliance closets.

If a device model or release is not clearly listed as fixed, assume it needs review until the vendor advisory says otherwise.

How to remediate

Patch first. Apply the updates Cisco published for this vulnerability, following the vendor’s install order, prerequisites, and reload guidance. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Reduce exposure until the vendor update can be installed.

If your data may have been exposed

Actively exploited edge vulnerabilities can lead to full device compromise, credential theft, traffic interception, or lateral movement into internal networks. Known ransomware use is not documented for this CVE in the provided facts, but that does not rule out other malicious use. If you suspect compromise, isolate the device, preserve logs and memory if collecting evidence, rotate credentials and certificates that traversed the router, and follow your incident response process. You can run a free exposure scan of your email addresses against known breach datasets to see whether associated accounts appear in prior dumps while you continue containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Small Business RV160, RV260, RV340, and RV345 Series Routers
WeaknessCWE-121
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities