CVE-2022-20701 encompasses multiple critical vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers, allowing attackers to execute arbitrary code, elevate privileges, bypass authentication, and cause denial of service. With a CVSS score of 7.8 (High), these vulnerabilities are easily exploitable with low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. This CVE is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite a lack of public exploit intelligence on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.