Executive brief
A vulnerability in the web-based management interface of Cisco RV320 and RV325 routers allows an authenticated, remote attacker with administrative privileges to execute arbitrary commands as root. The issue stems from improper validation of user-supplied input in HTTP POST requests, leading to OS command injection in the underlying Linux shell.
Affected products
- Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 up to 1.4.2.22
- Cisco RV325 Dual Gigabit WAN VPN Router 1.4.2.15 up to 1.4.2.22
Timeline
- 2019-01-23: advisory: Initial Cisco Security Advisory published
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-03: disclosed: NVD publication date