peter bassill · operator
$ cve CVE-2022-20841 JSON

CVE-2022-20841

9.0
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)

In your normal cycle

Critical by CVSS (9), but no sign of active exploitation.

Description

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Scoring

CVSS9.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS3.33% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2022-08-10
Last modified2026-06-17

Affected (18)

VendorProduct
ciscorv160
ciscorv160 firmware
ciscorv160w
ciscorv160w firmware
ciscorv260
ciscorv260 firmware
ciscorv260p
ciscorv260p firmware
ciscorv260w
ciscorv260w firmware
ciscorv340
ciscorv340 firmware
ciscorv340w
ciscorv340w firmware
ciscorv345
ciscorv345 firmware
ciscorv345p
ciscorv345p firmware

References

→ the Explorer  ·  watch your stack  ·  NVD