CVE-2022-20749 encompasses multiple critical vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers. These vulnerabilities, rated 9.8 CRITICAL, allow unauthenticated attackers to execute arbitrary code or commands, elevate privileges, bypass security controls, and cause denial of service. While there is no confirmed active exploitation, the high community discussion and media coverage, along with the existence of public proof-of-concept code, indicate significant interest and potential for future attacks. Organizations using affected devices should prioritize patching to mitigate these severe risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.24CPE matchmatch criteria | cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.