CVE-2022-20708
KEVlargeStack-Based Buffer Overflow in Cisco Small Business RV Series Routers
CISA: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
CVE-2022-20708 is a stack-based buffer overflow (CWE-121) in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers; it is one of a set of related flaws in these devices that also includes OS command injection (CWE-78). An attacker triggers it by sending crafted traffic to an affected router, which per the CVSS vector (AV:A/PR:L) requires an adjacent-network attacker with low privileges. Successful exploitation can fully compromise the device, allowing arbitrary code execution, privilege elevation, command execution, authentication bypass, fetching/running of unsigned software, or denial of service. Organizations running these small-business routers—typically small offices and branch sites—are affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03, and EPSS estimates a ~15% probability of exploitation within 30 days (96th percentile), though no public PoC is known.
What to do: Apply the fixed firmware released in Cisco's advisory for each affected model (RV160/260/340/345 series) per vendor instructions, as required by the CISA KEV listing. Until patched, restrict the routers' web management interface to trusted LAN access and remove it from direct internet exposure, and verify current firmware versions to identify unpatched units. Monitor device logs and CISA/EPSS reporting, since active exploitation is confirmed.
| cisco RV160 Series Routers (RV160, RV160W) | — |
| cisco RV260 Series Routers (RV260, RV260W) | — |
| cisco RV340 / RV340W Routers | — |
| cisco RV345 / RV345P Routers | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.
- Affected
- Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- rv340 firmware, rv340w firmware, rv345 firmware, rv345p firmware
- Weakness
- CWE-121, CWE-78
- Vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H