

Rewterz Threat Alert – DanaBot Trojan – Active IOCs
July 28, 2022
Rewterz Threat Alert – Hive Ransomware – Active IOCs
July 28, 2022
Rewterz Threat Alert – DanaBot Trojan – Active IOCs
July 28, 2022
Rewterz Threat Alert – Hive Ransomware – Active IOCs
July 28, 2022Severity
Medium
Analysis Summary
CVE-2022-20880
Multiple Cisco Small Business routers could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by insufficient validation of user fields within incoming HTTP packets. By sending a specially-crafted request to the web-based management interface, an attacker could exploit this vulnerability to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart.
CVE-2022-20881
Multiple Cisco Small Business routers could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by insufficient validation of user fields within incoming HTTP packets. By sending a specially-crafted request to the web-based management interface, an attacker could exploit this vulnerability to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart.
Impact
- Command Execution
Indicators Of Compromise
CVE
- CVE-2022-20880
- CVE-2022-20881
Affected Vendors
Cisco
Affected Products
- Cisco RV110W Wireless-N VPN Firewall
- Cisco RV130W Wireless-N Multifunction VPN Router
- Cisco RV215W Wireless-N VPN Router
- Cisco RV130 VPN Router
Remediation
Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.