Cisco plugs critical holes in small business routers
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-20699 | Stack Buffer Overflow RCE in Cisco Small Business RV Series Routers CVE-2022-20699 is a stack-based buffer overflow (CWE-121, caused by improper input-size validation per CWE-1284) in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers, one of a set of related flaws fixed in the same Cisco advisory. It can be triggered remotely without authentication by sending crafted requests to the router's network-facing services; the available public PoC demonstrates unauthenticated remote code execution against the RV340 via its SSL VPN interface. A successful attacker can execute arbitrary code or commands, elevate privileges, bypass authentication and authorization protections, install unsigned software, or crash the device (denial of service). Any organization running these small-business routers is affected, with the highest risk for devices whose web management or SSL VPN interface is reachable from the internet. The flaw is confirmed to be exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03, EPSS estimates a 72.5% probability of exploitation within 30 days, and at least one public proof-of-concept is available. Do: Upgrade all RV160, RV260, RV340/340W and RV345/345P routers to the fixed firmware released in Cisco's advisory, applying updates per vendor instructions as required by the CISA KEV entry. Until patched, limit exposure by restricting web management and SSL VPN to trusted source addresses or disabling SSL VPN where it is not needed. Because active exploitation and a public unauthenticated RCE PoC exist, prioritize internet-facing devices and check them for signs of compromise. | 9.8 | 72% | KEV PoC |
| largetens of thousands of internet-exposed routers (order of ~10^4 devices) | |
| CVE-2022-20749 +1 in the same advisory: …20712 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory. NVD description · AI analysis pending | 9.8 | 4% |
| — |
Full article315 words · extracted from helpnetsecurity.com · click to collapse
Cisco has patched 14 vulnerabilities affecting some of its Small Business RV Series routers, the worst of which may allow attackers to achieve unauthenticated remote code execution or execute arbitrary commands on the underlying Linux operating system.

“The Cisco PSIRT is aware that proof-of-concept exploit code is available for several of the vulnerabilities that are described in this advisory,” the company said in the accompanying security advisory. Luckily, the PoCs aren’t public – Cisco (mostly) refers to the exploits used by security researchers to “pwn” the Cisco RV340 router at the Pwn2Own hacking contest held in Austin, Texas, in November 2021.
About the vulnerabilities
The vulnerabilities affect Cisco Small Business RV160, RV260, RV340, and RV345 Series routers.
They have received consecutive CVE numbers starting with CVE-2022-20699 and ending with CVE-2022-20712. A final one has been marked CVE-2022-20749.
They may allow attackers to:
- Achieve RCE
- Elevate their privileges to root and execute commans
- Install and boot a malicious software image or execute unsigned binaries on an affected device
- View or alter information that is shared between an affected device and specific Cisco servers
- Defeat authentication protections and access the devices’s web UI
- Inject and execute arbitrary commands on the underlying operating system
- Upload arbitrary files to an affected device
- Cause a denial of service (DoS) condition in the login functionality of the web-based management interface
- Overwrite certain files on an affected device
“Some of the vulnerabilities are dependent on one another. Exploitation of one of the vulnerabilities may be required to exploit another vulnerability,” Cisco added.
Since there are no workarounds available, applying the provided security updates as soon as possible is advised.
The only temporary glitch in this plan is that while a security update for RV340 and RV345 Series routers is already available, the one for the RV160 and RV260 Series is still in the works and will be released sometime this month.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/02/03/cisco-small-business-routers/