Executive brief
A stack-based buffer overflow vulnerability in Cisco Small Business RV Series routers allows a remote, unauthenticated attacker to execute arbitrary code, elevate privileges, or cause a denial of service. The flaw stems from insufficient bounds checking when processing network traffic, potentially leading to full system compromise.
Affected products
- Cisco RV160 Series Routers up to (including) 1.0.01.05
- Cisco RV260 Series Routers up to (including) 1.0.01.05
- Cisco RV340 Series Routers up to (including) 1.0.03.24
- Cisco RV345 Series Routers up to (including) 1.0.03.24
Timeline
- 2022-02-17: disclosed: Initial analysis by NIST
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-03: exploited: Reported as exploited in the wild