CVE-2023-20118 is a critical command injection vulnerability affecting the web-based management interface of several Cisco Small Business Routers (RV016, RV042, RV042G, RV082, RV320, RV325). This flaw, due to improper user input validation, allows an authenticated, remote attacker to execute arbitrary commands with root-level privileges. Rated 7.2 HIGH on the CVSS scale, it requires valid administrative credentials but can lead to full system compromise and unauthorized data access. The vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog and significant community discussion, though public exploit code is not readily available. Cisco will not release patches for these end-of-life products, recommending administrators disable the affected feature as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv016_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv042_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv042g_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv082_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv320_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.