ZeroHour

CVE-2023-20118

KEVlarge

Authenticated Command Injection in Cisco Small Business RV Series Routers

CISA: Cisco Small Business RV Series Routers Command Injection Vulnerability

CVSS 3.1
7.2 high
EPSS
54%p99
Published
()
KEV added
AI analysis

CVE-2023-20118 is a command injection flaw (CWE-77) in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 routers, caused by improper validation of user input within incoming HTTP packets. An authenticated remote attacker who already holds valid administrative credentials sends a crafted HTTP request to the management interface and can execute arbitrary commands with root-level privileges, gaining full device control and access to unauthorized data. All organizations running these six small-business router models are affected, and Cisco has stated it will not release any software update, leaving only a workaround. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-03, carries a high EPSS score of 54.1%, and news reporting around that period describes campaigns (e.g., ViciousTrap, which built a global honeypot from roughly 5,300 compromised devices) abusing Cisco router flaws, with botnet operators such as PolarEdge also targeting Cisco small-business routers. These end-of-service devices are therefore under active, in-the-wild exploitation and should be treated as high-priority for mitigation.

What to do: No firmware fix will ever be released, so apply Cisco's workaround by disabling the affected feature or restricting the web management interface to trusted management hosts only (disable remote/internet-facing management). Check device logs and configurations for signs of compromise, including unexpected configuration changes or outbound connections indicating botnet implants. Because these routers are end-of-service, plan migration to supported models and, for federal agencies, follow BOD 22-01 mitigation guidance or discontinue use.

Affected
Cisco RV016 Router (firmware)all firmware versions; no patched release available
Cisco RV042 Router (firmware)all firmware versions; no patched release available
Cisco RV042G Router (firmware)all firmware versions; no patched release available
Cisco RV082 Router (firmware)all firmware versions; no patched release available
Cisco RV320 Router (firmware)all firmware versions; no patched release available
Cisco RV325 Router (firmware)all firmware versions; no patched release available
Estimated exposure
largetens of thousands of internet-exposed devices (order-of-magnitude estimate; at least ~5,300 already confirmed compromised in one reported campaign) — Cisco's RV-series small-business routers had a large installed base and remain common on the public internet per public scan data, with tens of thousands of RV04x/RV32x management interfaces historically exposed, and a single recent…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data. To exploit this vulnerability, an attacker would need to have valid administrative credentials on the affected device. Cisco has not and will not release software updates that address this vulnerability. However, administrators may disable the affected feature as described in the Workarounds ["#workarounds"] section. {{value}} ["%7b%7bvalue%7d%7d"])}]]

CISA Known Exploited Vulnerability
Affected
Cisco Small Business RV Series Routers
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
rv016 firmware, rv042 firmware, rv042g firmware, rv082 firmware, rv320 firmware, rv325 firmware
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news