CVE-2023-20117 describes multiple command injection vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers. An authenticated, remote attacker can exploit these flaws due to insufficient input validation, allowing arbitrary command execution as the root user on the underlying Linux operating system. Rated 7.2 HIGH (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), successful exploitation requires valid Administrator credentials and can lead to full compromise of the device. There are no known active exploits, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV entries, though it has received some community discussion and media coverage. Cisco has not released patches for these vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.1.13CPE matchmatch criteria | cpe:2.3:o:cisco:rv320_firmware:1.5.1.13:*:*:*:*:*:*:* | ||
1.5.1.13CPE matchmatch criteria | cpe:2.3:o:cisco:rv325_firmware:1.5.1.13:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.