VYPR
Unrated severityNVD Advisory· Published Feb 10, 2022· Updated Nov 6, 2024

Cisco Small Business RV Series Routers Vulnerabilities

CVE-2022-20711

Description

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco Small Business RV340, RV340W, RV345, and RV345P routers have a critical missing authentication vulnerability in the NGINX configuration that allows network-adjacent attackers to disclose stored web session tokens.

Vulnerability

CVE-2022-20711 affects Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers. The vulnerability exists within the configuration of the NGINX web server. The issue is that the NGINX server lacks authentication prior to allowing access to certain functionality, which can expose sensitive information [1][2]. This allows an attacker to disclose stored web session tokens [2].

Exploitation

Exploitation requires network-adjacent access (logical adjacency, not necessarily physical) and no authentication [2]. An attacker can send requests to the affected NGINX web server that would normally require authentication. The server does not verify identity before granting access to functionality that discloses stored web session tokens [2]. This could be used in conjunction with other vulnerabilities to chain further attacks [1].

Impact

An attacker can successfully exploit this vulnerability to disclose sensitive information, specifically stored web session tokens. With these tokens, the attacker may impersonate authenticated users and potentially achieve further compromise, such as executing commands or escalating privileges. The CVSS score for this vulnerability is 6.3, with a vector of AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N, indicating high confidentiality impact, low integrity impact, and no availability impact [2].

Mitigation

Cisco has released software updates to address this vulnerability. As of the advisory publication date (February 10, 2022), fixed versions are available. Customers are advised to upgrade to the appropriate fixed software version listed in Cisco's security advisory [1]. No workarounds are available, but the vulnerability requires network-adjacent access, which limits exposure.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.