← Vulnerability feed

Vulnerability record · CVE-2023-20118 · published 13 April 2023

CVE-2023-20118: Cisco Small Business RV Series Routers Command Injection

Cisco · Rv016 Firmware

The web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 routers fails to properly validate user input in incoming HTTP packets, allowing command injection. Cisco has stated it will not release software updates for this flaw, so affected devices remain vulnerable unless the feature is disabled or the product is retired.

7.2 CVSS 3.1 High CISA KEV since 3 Mar 2025 EPSS 54% · top 1.0% CWE-77 · Command injection
7.2CVSS 3.1 base score
54%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
6Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data. To exploit this vulnerability, an attacker would need to have valid administrative credentials on the affected device. Cisco has not and will not release software updates that address this vulnerability. However, administrators may disable the affected feature as described in the Workarounds ["#workarounds"] section. {{value}} ["%7b%7bvalue%7d%7d"])}]]

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw allows remote root-level command execution, is listed in CISA KEV, has a very high EPSS score, and no patch will be provided.

What it is

The web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 routers fails to properly validate user input in incoming HTTP packets, allowing command injection. Cisco has stated it will not release software updates for this flaw, so affected devices remain vulnerable unless the feature is disabled or the product is retired.

Impact

An attacker with valid administrative credentials can execute arbitrary commands and gain root-level privileges on the device, leading to unauthorized data access and full compromise of the router.

Attack surface

Reachable remotely over the network through the web-based management interface via a crafted HTTP request. Exploitation requires valid administrative credentials; no user interaction is needed.

Exploitation

The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog with a high EPSS probability (0.54107, 98.95th percentile), indicating active exploitation is likely. No ransomware campaign use is documented.

What to do

  • Apply the vendor workarounds in Cisco's advisory to disable the affected feature, since no software update will be released.
  • If workarounds are not feasible, discontinue use of the affected RV016, RV042, RV042G, RV082, RV320, and RV325 routers.
  • Restrict access to the web-based management interface to trusted management networks only.
  • Enforce strong, unique administrative credentials and rotate them regularly.
  • Follow applicable BOD 22-01 guidance for cloud services if the device is exposed.

Detection

  • Monitor HTTP requests to the router management interface for command injection patterns or unusual input.
  • Alert on unexpected outbound connections or processes spawned from the router's web management service.
  • Audit administrative logins for anomalous source IPs or times.
  • Review router logs for signs of unauthorized configuration changes or data access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-20118 to the Known Exploited Vulnerabilities catalog on 3 March 2025 as "Cisco Small Business RV Series Routers Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 March 2025.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-20118 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2019-1653Cisco RV320/RV325 router web interface improper access controlThe web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers has improper access controls for URLs, lettin…KEVEPSS 100%analysed7.2CVE-2019-1652Cisco RV320/RV325 web interface command injectionThe web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers fails to properly validate user-supplied inpu…KEVEPSS 96%analysed9.8CVE-2023-20025Cisco rv016 firmware authentication bypass by spoofing vulnerabilityA vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers could allow an unauthenticated,…EPSS 1.6%9.1CVE-2024-20520Cisco rv042 firmware stack-based buffer overflow vulnerabilityA vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, A…EPSS 0.61%9.1CVE-2024-20521Cisco rv042 firmware stack-based buffer overflow vulnerabilityA vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, A…EPSS 0.66%9.1CVE-2024-20518Cisco rv042 firmware stack-based buffer overflow vulnerabilityA vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, A…EPSS 0.61%9.1CVE-2024-20519Cisco rv042 firmware stack-based buffer overflow vulnerabilityA vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, A…EPSS 0.61%8.1CVE-2019-1828Cisco rv320 firmware broken cryptographic algorithm vulnerabilityA vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthentic…EPSS 0.70%

Source: NIST National Vulnerability Database (record CVE-2023-20118), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.