CVE-2022-20700 represents multiple critical vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers. With a CVSS score of 9.8 (Critical), these vulnerabilities allow unauthenticated remote attackers to execute arbitrary code, elevate privileges, bypass authentication, and cause denial of service. This vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog, and has garnered significant community attention and media coverage, despite no public Metasploit or ExploitDB modules being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.01.05CPE matchmatch criteria | cpe:2.3:o:cisco:rv160_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.