cbcvebase.
CVE-2022-20705
published 2022-02-10

CVE-2022-20705: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute…

PriorityP191critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
80.03%
99.6th percentile
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

Affected

11 ranges
VendorProductVersion rangeFixed in
ciscocisco_small_business_rv_series_router_firmware
ciscorv160_firmware<= 1.0.01.05
ciscorv160w_firmware<= 1.0.01.05
ciscorv260_firmware<= 1.0.01.05
ciscorv260p_firmware<= 1.0.01.05
ciscorv260w_firmware<= 1.0.01.05
ciscorv340_firmware<= 1.0.03.24
ciscorv340w_firmware<= 1.0.03.24
ciscorv345_firmware<= 1.0.03.24
ciscorv345p_firmware<= 1.0.03.24
ciscosmall_business_rv_series_routers

Detection & IOCsextracted from sources · hover to see the quote

path/form-file-upload
path/upload
path/tmp/websession/token/
path/tmp/upload
cookiesessionid
path/www/cgi-bin/
filenameupload.cgi
filenamejsonrpc.cgi
  • CVE-2022-20705 is a session ID directory traversal authentication bypass: nginx checks for the existence of a file at /tmp/websession/token/$cookie_sessionid to grant access to /upload. An attacker can bypass authentication by manipulating the sessionid cookie value to traverse to an existing file path.
  • Monitor for unauthenticated HTTP POST requests to /upload or /form-file-upload on Cisco RV160/RV260/RV340/RV345 routers, especially from WAN interfaces if remote management is enabled.
  • The Metasploit module chains CVE-2022-20705 (auth bypass via session ID directory traversal) with CVE-2022-20707 (command injection) to achieve unauthenticated RCE as www-data on firmware versions 1.0.03.24 and below.
  • Alert on firmware versions RV340/RV345 <= 1.0.03.24 and RV160/RV260 <= 1.0.01.05 as vulnerable; patched versions are RV340/RV345 1.0.03.26 and RV160/RV260 1.0.01.07.
  • Suspicious file writes to /tmp/upload directory on Cisco RV series routers may indicate exploitation of the unauthenticated file upload endpoint.
  • ·The /upload endpoint authentication bypass (CVE-2022-20705) is only exploitable from the WAN interface if remote management is explicitly enabled; by default it is only accessible from the LAN interface.
  • ·Not all CVEs in the Cisco advisory (cisco-sa-smb-mult-vuln-KA9PK6D) apply to all affected product models; check the vendor advisory for per-product applicability.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.