Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2022-20705

CVE-2022-20705: Cisco RV340 Firmware RCE Vulnerability

CVE-2022-20705 is a remote code execution vulnerability in Cisco RV340 Firmware that allows attackers to execute arbitrary code and elevate privileges. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2022-20705 Overview

CVE-2022-20705 is part of a cluster of vulnerabilities affecting Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers. The flaws allow a remote, unauthenticated attacker to execute arbitrary code, elevate privileges, run arbitrary commands, bypass authentication, fetch and run unsigned software, or trigger denial of service. The weaknesses are tracked under [CWE-121] stack-based buffer overflow and [CWE-787] out-of-bounds write. Cisco published the issues in its consolidated advisory cisco-sa-smb-mult-vuln-KA9PK6D.

Critical Impact

A network-adjacent attacker can fully compromise affected routers without authentication, gaining code execution at elevated privilege on a perimeter device.

Affected Products

  • Cisco Small Business RV160 and RV160W Routers (and firmware)
  • Cisco Small Business RV260, RV260P, and RV260W Routers (and firmware)
  • Cisco Small Business RV340, RV340W, RV345, and RV345P Routers (and firmware)

Discovery Timeline

  • 2022-02-10 - CVE-2022-20705 published to NVD
  • 2024-11-21 - Last updated in NVD database

Technical Details for CVE-2022-20705

Vulnerability Analysis

CVE-2022-20705 belongs to a set of 15 vulnerabilities disclosed by Cisco in the web-based management interface and underlying services of the RV Series Small Business Routers. The flaw is reachable over the network without authentication and without user interaction, which is why it is classified as remotely exploitable with high impact to confidentiality, integrity, and availability.

The advisory groups multiple weakness classes, including stack-based buffer overflow ([CWE-121]) and out-of-bounds write ([CWE-787]) in HTTP request handlers used by the router management plane. Successful exploitation lets an attacker overwrite control data on the stack and divert execution.

EPSS rates the probability of exploitation at 80.208%, placing this issue in the 99th percentile across all CVEs. Public technical details are available through Zero Day Initiative advisories ZDI-22-409, ZDI-22-410, and ZDI-22-415, and a Packet Storm advisory covers the authentication bypass and command injection chain.

Root Cause

The root cause is improper validation of attacker-controlled input passed to fixed-size stack buffers in the router's web management components. Insufficient bounds checking allows the input length or content to exceed the buffer, corrupting adjacent stack memory including saved return addresses.

Attack Vector

An attacker sends crafted HTTP requests to the management interface of an affected device. Because authentication can be bypassed in the same vulnerability cluster, the attacker does not need valid credentials. Exploitation results in arbitrary code execution on the router operating system with elevated privileges.

No verified public proof-of-concept code is included in the enriched data. Refer to the Cisco Security Advisory and the ZDI advisories for technical breakdown.

Detection Methods for CVE-2022-20705

Indicators of Compromise

  • Unexpected outbound connections initiated by the router to attacker infrastructure, particularly from management or WAN interfaces.
  • New or modified administrative accounts, SSH keys, or firewall rules on the router that were not created by an authorized administrator.
  • Unsigned or unrecognized firmware images, scripts, or binaries staged in writable filesystem locations on the device.
  • Web management logs showing malformed or oversized HTTP POST requests preceding service crashes or restarts.

Detection Strategies

  • Monitor HTTP and HTTPS traffic to the router management interface for anomalous request sizes, malformed headers, or requests to undocumented endpoints.
  • Alert on router reboots, daemon crashes, or watchdog resets that correlate with inbound management traffic.
  • Inspect configuration drift using out-of-band tools such as RANCID or Cisco Prime to detect unauthorized changes.

Monitoring Recommendations

  • Forward syslog and authentication events from RV Series devices to a central log platform and alert on management plane errors.
  • Restrict and log all access attempts to the device web UI, especially from WAN-facing interfaces.
  • Track firmware version inventory and flag devices still running pre-fix releases identified in the Cisco advisory.

How to Mitigate CVE-2022-20705

Immediate Actions Required

  • Apply the fixed firmware identified in the Cisco Security Advisory cisco-sa-smb-mult-vuln-KA9PK6D to all affected RV160, RV260, RV340, and RV345 series devices.
  • Disable remote management on the WAN interface until patches are deployed and verified.
  • Rotate administrative credentials and review SSH keys after patching to invalidate any credentials that may have been captured.
  • Audit router configuration, firewall rules, and VPN tunnels for unauthorized changes.

Patch Information

Cisco released fixed firmware images for the affected RV Series platforms. Consult the Cisco Security Advisory for the minimum fixed release matching each model. Cisco's advisory states that no workarounds fully address the issue — only the updated firmware does.

Workarounds

  • Restrict access to the router web management interface to trusted internal management subnets using access control lists.
  • Disable web-based management from the WAN side via the device administrative settings.
  • Place affected routers behind an upstream firewall that filters inbound traffic to TCP management ports until firmware can be updated.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.