Junglewise Threat Intelligence

CVE-2023-20118: Cisco Small Business RV Series Routers Command Injection Vulnerability

CVE-2023-20118 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2025-03-03

Vendors: Cisco.

Executive brief

A command injection vulnerability in the web-based management interface of Cisco Small Business RV Series routers allows an authenticated, remote attacker with administrative credentials to execute arbitrary commands. The flaw is caused by improper validation of user input in HTTP packets, potentially leading to root-level access and unauthorized data retrieval.

Affected products

  • Cisco RV016
  • Cisco RV042
  • Cisco RV042G
  • Cisco RV082
  • Cisco RV320
  • Cisco RV325

Timeline

  • 2023-05-17: disclosed: Original Cisco advisory date (implied by CVE year and vendor reference)
  • 2025-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-03-03: exploited: Confirmed exploited in the wild per CISA KEV entry