CVE-2022-20827

CRITICAL

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service...

Affects 18 products across 1 vendor.

BCS7.76
CVSS 3.110.0
EPSS1.9%
Percentile79th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

CWE-120: Buffer Copy without Checking Size (Classic Buffer Overflow)

Program copies data to a buffer without verifying the source data fits within the destination.

Related Attack Patterns (CAPEC)
CAPEC-8 Buffer Overflow in an API Call
via CWE-120
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-120
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-120
CAPEC-14 Client-side Injection-induced Buffer Overflow
via CWE-120
CAPEC-24 Filter Failure through Buffer Overflow
via CWE-120
Show all 18
via CWE-78
via CWE-78
via CWE-78
via CWE-78
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device.

BSID: BS-2022-GLOBAL-311051-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2022-20827?
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device.
What is the CVSS score for CVE-2022-20827?
CVE-2022-20827 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 1.9%.
Is CVE-2022-20827 actively exploited?
No confirmed active exploitation of CVE-2022-20827 as of 2026-09-25.
How do I remediate CVE-2022-20827?
Priority: IMMEDIATE. Advisory: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-mult-vuln-CbVp4SUR PSIRT: [email protected]
What systems are affected by CVE-2022-20827?
CVE-2022-20827 affects: Cisco, Cisco, Cisco, Cisco, Cisco, Cisco, Cisco, Cisco.
Vulnerability Details
CVE IDCVE-2022-20827
BSIDBS-2022-GLOBAL-311051-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2022-08-10
Last Modified2026-06-17
ICS Relevance90%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An unauthenticated, remote attacker can exploit these vulnerabilities to execute arbitrary code or cause a denial of service (DoS) condition on the affected devices.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductAffected Versions
Cisco Rv340W Firmware < 1.0.03.26
Cisco Rv340W < 1.0.03.26
Cisco Rv340 Firmware < 1.0.03.26
Cisco Rv340 < 1.0.03.26
Cisco Rv345 Firmware < 1.0.03.26
Cisco Rv345 < 1.0.03.26
Cisco Rv345P Firmware < 1.0.03.26
Cisco Rv345P < 1.0.03.26
Cisco Rv160 Firmware < 1.0.01.05
Cisco Rv160 < 1.0.01.05
Cisco Rv160W Firmware < 1.0.01.05
Cisco Rv160W < 1.0.01.05
Cisco Rv260 Firmware < 1.0.01.05
Cisco Rv260 < 1.0.01.05
Cisco Rv260P Firmware < 1.0.01.05
Cisco Rv260P < 1.0.01.05
Cisco Rv260W Firmware < 1.0.01.05
Cisco Rv260W < 1.0.01.05
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 1517 Days
CISA known-exploitedNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash09c8390650d66129ac1440d51e02db3e7c2dd91f92aed41b14ac9f0f6efc5765f5e186ef5fac290f874153c2fae2c9330a6658dd96b657be255dd24abc4a054f
Related CVEs affecting Cisco
CVE-2018-0222 10.0 A vulnerability in Cisco Digital Network Architecture (DNA) Center could allo... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2018-0101 10.0 A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Ci... CVE-2021-1388 10.0 A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO)... CVE-2008-1157 10.0 Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 creates a process...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →