VYPR
Unrated severityNVD Advisory· Published Apr 5, 2023· Updated Oct 25, 2024

Cisco Small Business RV016, RV042, RV042G, RV082 , RV320, and RV325 Routers Cross-Site Scripting Vulnerabilities

CVE-2023-20138

Description

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device and then persuading a user to visit specific web pages that include malicious payloads. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Cisco has not released software updates that address these vulnerabilities.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco Small Business RV series routers contain multiple stored XSS vulnerabilities in the web-based management interface due to insufficient input validation, with no available patches.

Vulnerability

Multiple cross-site scripting (XSS) vulnerabilities exist in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 routers (all firmware versions prior to any fix). The vulnerabilities are caused by insufficient input validation of user-supplied data by the interface, allowing injection of malicious scripts. No software updates have been released [1].

Exploitation

An unauthenticated, remote attacker can exploit these vulnerabilities by sending crafted HTTP requests to an affected device containing malicious payloads. The attacker must then persuade a user of the interface to visit specific web pages that include the injected payloads. The attacker does not require any prior authentication or local network access, as the management interface is exposed if remote management is enabled [1].

Impact

Successful exploitation allows the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. This could lead to session hijacking, credential theft, or other client-side attacks affecting the device administrator [1].

Mitigation

Cisco has not released software updates addressing these vulnerabilities. No workarounds are available. Mitigations involve disabling remote management and, for RV016, RV042, RV042G, and RV082 routers, also blocking access to ports 443 and 60443 on the WAN interface. To disable remote management, navigate to Firewall > General and uncheck Remote Management. To block ports, create access rules under Firewall > Access Rules to deny traffic from WAN sources. These steps will keep the router accessible via the LAN interface [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.