← All CVEs

CVE-2023-20118

medium · 6.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added 2025-03-03Remediation due 2025-03-24

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data. To exploit this vulnerability, an attacker would need to have valid administrative credentials on the affected device. Cisco has not and will not release software updates that address this vulnerability. However, administrators may disable the affected feature as described in the Workarounds ["#workarounds"] section. {{value}} ["%7b%7bvalue%7d%7d"])}]]

6.5
CVSS
54.1%
EPSS (exploit prob.)
99th
EPSS percentile
2023-04-13
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
ciscorv016_firmwareall versions
ciscorv016all versions
ciscorv042_firmwareall versions
ciscorv042all versions
ciscorv042g_firmwareall versions
ciscorv042gall versions
ciscorv082_firmwareall versions
ciscorv082all versions
ciscorv320_firmwareall versions
ciscorv320all versions
ciscorv325_firmwareall versions
ciscorv325all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-20118