CVE-2022-20709 encompasses multiple critical vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers. These flaws allow unauthenticated attackers to execute arbitrary code, elevate privileges, bypass authentication, and cause denial of service. With a CVSS score of 7.5 (High) and an AV:N/AC:L vector, exploitation is network-based and low complexity, potentially leading to full system compromise. While not currently listed in CISA's KEV catalog, the vulnerability has garnered significant community attention with 12 mentions and two media articles discussing available exploits, though no public Metasploit or Nuclei modules are yet identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.