cbcvebase.
CVE-2022-20842
published 2022-08-10

CVE-2022-20842: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute…

PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.64%
73.7th percentile
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Affected

6 ranges
VendorProductVersion rangeFixed in
ciscocisco_small_business_rv_series_router_firmware
ciscorv340_firmware< 1.0.03.281.0.03.28
ciscorv340w_firmware< 1.0.03.281.0.03.28
ciscorv345_firmware< 1.0.03.281.0.03.28
ciscorv345p_firmware< 1.0.03.281.0.03.28
ciscosmall_business_rv_series_routers

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability affects the web-based management interface of Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers; monitor for unauthenticated remote requests targeting the management interface that may indicate exploitation attempts (buffer overflow or command injection via CWE-120/CWE-77/CWE-78)
  • ·No workarounds are available; patching via Cisco software updates is the only remediation path for CVE-2022-20842 and related vulnerabilities in this advisory.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.