VYPR
Unrated severityNVD Advisory· Published Aug 10, 2022· Updated Nov 1, 2024

Cisco Small Business RV Series Routers Vulnerabilities

CVE-2022-20841

Description

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple unauthenticated remote code execution and DoS vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 series routers due to insufficient input validation.

Vulnerability

Multiple vulnerabilities exist in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers. CVE-2022-20842 is a remote code execution and denial of service vulnerability in the web-based management interface of RV340, RV340W, RV345, and RV345P routers, due to insufficient validation of user-supplied input [1]. CVE-2022-20827 is a command injection vulnerability in the web filter database update feature affecting RV160, RV260, RV340, and RV345 series routers, also due to insufficient input validation [1].

Exploitation

An unauthenticated, remote attacker can exploit CVE-2022-20842 by sending crafted HTTP input to the web-based management interface [1]. For CVE-2022-20827, the attacker submits crafted input to the web filter database update feature [1]. No authentication or user interaction is required.

Impact

Successful exploitation of either vulnerability allows the attacker to execute arbitrary code with root privileges on the underlying operating system. For CVE-2022-20842, the attacker can also cause the device to reload, resulting in a denial of service condition [1]. CVE-2022-20827 specifically allows command injection as root [1]. The CVSS base score for CVE-2022-20842 is 9.8 (Critical) [1].

Mitigation

Cisco has released software updates that address these vulnerabilities. There are no workarounds [1]. Affected users should apply the updates as soon as possible.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.