LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-20708: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-20708 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary…

CVE-2022-20708 is a stack-based buffer overflow in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers. According to CISA, a successful attack could let an adversary execute arbitrary code, elevate privileges, run arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service. These devices commonly sit at the network edge, so the flaw matters to any organization that still relies on them for routing, VPN, or remote access.

Defenders should treat this as a high-priority edge-device issue: confirm whether the listed models are present, apply the vendor updates CISA directs, and watch for signs of abuse until those updates are in place. Specifics such as exact firmware builds and attack prerequisites must be confirmed against the Cisco advisory.

How it works

The weakness is classified as CWE-121 (stack-based buffer overflow). In this class of flaw, input is written past the end of a fixed-size buffer allocated on the stack. That overwrite can corrupt adjacent stack data, including control information the CPU uses to decide where execution continues.

An attacker who can reach the vulnerable interface supplies crafted input that triggers the overflow. Once control flow is diverted, the attacker may achieve the outcomes CISA lists: arbitrary code or command execution, privilege elevation, authentication/authorization bypass, loading of unsigned software, or a crash that produces denial of service. Public detail on the precise packet, field, or service that triggers the overflow is limited; treat any remotely reachable management, VPN, or web service on these routers as potentially in scope until the vendor advisory is reviewed.

Am I affected? How to find it in your systems

These Cisco Small Business RV-series routers are typically deployed as small-office/home-office or branch edge devices—handling NAT, firewalling, site-to-site or remote-access VPN, and sometimes basic wireless. Inventory steps:

If the device is internet-facing or reachable from untrusted networks, prioritize it. Absence of a public proof-of-concept does not mean the devices are safe; confirm patch status directly.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the fixed firmware for the exact RV160/RV260/RV340/RV345 model from Cisco, verify the image integrity, and install it during a maintenance window. After reboot, re-check the running version and confirm management services are still reachable only from intended sources.

Additional hardening appropriate to this device class:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These steps only buy time; they do not replace the firmware update.

If your data may have been exposed

Actively exploited edge vulnerabilities frequently lead to full network compromise and data theft. Known ransomware use of this CVE is not documented, yet the range of impacts CISA describes (code execution, auth bypass, unsigned software) means a breach cannot be ruled out if the device was unpatched and reachable. Review logs for indicators of compromise, rotate credentials that traversed the device, and examine downstream systems for lateral movement. You can also run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Small Business RV160, RV260, RV340, and RV345 Series Routers
WeaknessCWE-121
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities