ZeroHour

CVE-2022-20701

KEVlarge

Actively Exploited Stack-Based Buffer Overflow in Cisco RV Series Routers

CISA: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

CVSS 3.1
7.8 high
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2022-20701 is a stack-based buffer overflow (CWE-121, with an associated out-of-bounds write, CWE-787) in the firmware of Cisco Small Business RV160, RV260, RV340, and RV345 series routers, disclosed as part of a multi-vulnerability advisory that also covers flaws enabling arbitrary command execution, authentication bypass, unsigned-software execution, and denial of service. Per the CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U), this particular flaw requires low-privileged local access with no user interaction and is triggered when the router's firmware mishandles crafted input, overwriting a stack buffer. A successful attacker can execute arbitrary code, elevate privileges to take control of the router, or crash the device. Any organization running the affected Cisco Small Business RV-series routers — including RV340, RV340W, RV345, and RV345P models — is affected, and these devices are widely used in small-office and SMB networks. The flaw is actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03 and EPSS assigns a 9.7% chance of exploitation within 30 days (95th percentile), though no public proof-of-concept is known and ransomware use is unconfirmed.

What to do: Apply the firmware updates Cisco released for the RV160, RV260, RV340/RV340W, and RV345/RV345P series per the vendor advisory, as required by the CISA KEV entry (specific fixed-version numbers are not in the source data, so consult Cisco's advisory for the correct build). Restrict router management interfaces to trusted networks or VPN access and prioritize patching any internet-facing RV-series devices. Inventory your estate for these models and verify current firmware versions against Cisco's affected-products list before upgrading.

Affected
Cisco Small Business RV160 Series Routers
Cisco Small Business RV260 Series Routers
Cisco Small Business RV340 / RV340W Router Firmware
Cisco Small Business RV345 / RV345P Router Firmware
Estimated exposure
largeTens of thousands of internet-exposed RV-series devices (estimated, likely 100,000+ units installed overall) — Public internet scans (e.g., Shodan) of Cisco RV-series management interfaces suggest on the order of tens of thousands of exposed devices, and these small-business routers are broadly deployed in SOHO/SMB and ISP- or MSP-managed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

CISA Known Exploited Vulnerability
Affected
Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
rv340 firmware, rv340w firmware, rv345 firmware, rv345p firmware
Weakness
CWE-121, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news