CVE-2024-20520

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 787
CWE ID 121

Summary

CVE-2024-20520 is a newly disclosed vulnerability affecting the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers. This issue enables authenticated, Administrator-level, remote attackers to execute arbitrary code as the root user. To exploit this vulnerability, an attacker must possess valid Administrator credentials on the targeted device. The root cause of this vulnerability lies in the routers' improper validation of user-supplied input in their web-based management interface. A malicious attacker could potentially exploit this weakness by sending crafted HTTP requests to an affected device. A successful attack could result in the execution of arbitrary code on the underlying operating system, elevating the attacker's privileges to the highest level.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Rv320 Firmware
  • Cisco Rv325 Firmware

Affected Vendors

  • Cisco