CVE-2023-20118

Confirmed PUBLISHED

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could...

Cisco · Cisco Small Business RV Series Router Firmware
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
6.5 Medium

At a Glance

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data. To exploit this vulnerability, an attacker would need to have valid administrative credentials on the affected device. Cisco has not and will not release software updates that address this vulnerability. However, administrators may disable the affected feature as described in the Workarounds ["#workarounds"] section. {{value}} ["%7b%7bvalue%7d%7d"])}]]

nessus_scanner edge cisa
CVE Published
Apr 05, 2023
Exploitation Reported
Mar 03, 2025
CVSS
6.5 Medium
EPSS
Remote Low complexity No user interaction

Affected Versions

Vendor Product Version Status
Cisco
Cisco Small Business RV Series Router Firmware

1.0.1.17

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.0.2.03

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.1.0.09

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.1.1.19

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.1.1.06

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.2.1.13

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.2.1.14

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.3.1.12

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.3.2.02

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.3.1.10

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.4.2.15

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.4.2.17

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.4.2.19

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.4.2.20

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.4.2.22

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.5.1.05

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.5.1.11

Affected
Cisco
Cisco Small Business RV Series Router Firmware

1.5.1.13

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.