LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-20118: Cisco Small Business RV Series Routers Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-20118 to its Known Exploited Vulnerabilities catalog on Mar 3, 2025, with a federal patch deadline of Mar 24, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker…

CVE-2023-20118 is a command injection vulnerability affecting the web-based management interface of multiple Cisco Small Business RV Series Routers. An authenticated remote attacker who can reach that interface may inject operating-system commands and obtain root-level privileges, giving them the ability to read unauthorized data or take full control of the device. Because these routers commonly sit at the network edge of small and mid-size organizations, a successful compromise can expose internal traffic, credentials, or connected systems.

Defenders should treat any internet-reachable or poorly segmented management interface as high risk until the device is confirmed patched or removed from service. Specifics such as exact model lists and fixed software releases must be verified against the current Cisco advisory.

How it works

The underlying weakness is CWE-77 (Improper Neutralization of Special Elements used in a Command). The web management interface accepts input that is later passed to a system shell without adequate sanitization. An attacker who already holds valid credentials for the interface can craft requests that insert additional shell commands. Those commands execute with the elevated privileges of the management process, resulting in root access on the router. No unauthenticated remote code execution path is described; authentication is required. Exact injection points and payload formats are not publicly detailed here and should be confirmed only from the vendor advisory.

Am I affected? How to find it in your systems

Cisco Small Business RV Series Routers are typically deployed as edge or branch gateways in small-office and remote-site networks. Inventory every device that presents a Cisco RV web management interface (HTTP/HTTPS on the LAN or WAN side). Record the exact model and firmware version displayed on the device status page or via the CLI. Compare those versions against the list of affected releases published by Cisco; do not rely on generic version ranges.

Telemetry signs of exploitation may include sudden root-level configuration changes, unexpected outbound connections, or new administrative accounts. Because the vulnerability requires authentication, also audit for credential-stuffing or brute-force activity against the management interface.

How to remediate

Apply the software update or mitigation package identified in the official Cisco advisory for CVE-2023-20118. CISA directs organizations to follow the vendor’s instructions, apply any applicable Binding Operational Directive 22-01 guidance for cloud-managed instances, or discontinue use of the product if no mitigation is available. After patching, re-verify the firmware version and regenerate any administrative credentials that may have been exposed.

If you can't patch immediately

Until the vendor update can be installed, reduce the attack surface with compensating controls. Place the router behind a firewall that permits management traffic only from a short list of trusted administrative addresses. If the device supports it, disable the web management interface entirely and rely on console or SSH access from a secured segment. Deploy network-based detection rules that alert on anomalous command strings or unexpected process activity originating from the router’s management IP. Virtual patching via a web application firewall may block known malicious request patterns, but such rules must be validated against the specific interface behavior and should not be considered a permanent substitute for the official fix. Continuous monitoring of configuration integrity and outbound traffic remains essential.

If your data may have been exposed

Actively exploited router vulnerabilities frequently lead to broader network compromise and data exposure. If logs or other indicators suggest the management interface was reached by an unauthorized party, treat the device and any credentials stored on it as compromised. Reset administrative passwords, review connected systems for lateral movement, and consider rotating any secrets that traversed the router. Readers can also run a free exposure scan of their email addresses against known breach data sets to determine whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Small Business RV Series Routers
WeaknessCWE-77
Added to CISA KEVMar 3, 2025
Federal patch deadlineMar 24, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities