{"cveID":"CVE-2023-20118","vendorProject":"Cisco","product":"Small Business RV Series Routers","vulnerabilityName":"Cisco Small Business RV Series Routers Command Injection Vulnerability","dateAdded":"2025-03-03","shortDescription":"Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-03-24","knownRansomwareCampaignUse":"Unknown","notes":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5 ; https://nvd.nist.gov/vuln/detail/CVE-2023-20118","cwes":["CWE-77"],"year":2023,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2023-20118","technique":"T1068","technique_name_at_mapping":"Exploitation for Privilege Escalation","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"Cisco Small Business Router models RV016, RV042, RV042G, RV082, RV320, and RV325 perform improper validation of HTTP packet user input. An authenticated attacker can craft these requests and send them, leading to arbitrary command execution.","references":["https://medium.com/@scottbolen/cyber-threat-intelligence-cti-report-cve-2023-20118-cisco-small-business-routers-remote-code-185980e9e8e6"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-20118","technique":"T1078","technique_name_at_mapping":"Valid Accounts","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"Cisco Small Business Router models RV016, RV042, RV042G, RV082, RV320, and RV325 perform improper validation of HTTP packet user input. An authenticated attacker can craft these requests and send them, leading to arbitrary command execution.","references":["https://medium.com/@scottbolen/cyber-threat-intelligence-cti-report-cve-2023-20118-cisco-small-business-routers-remote-code-185980e9e8e6"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-20118","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"code_execution","comments":"Cisco Small Business Router models RV016, RV042, RV042G, RV082, RV320, and RV325 perform improper validation of HTTP packet user input. An authenticated attacker can craft these requests and send them, leading to arbitrary command execution.","references":["https://medium.com/@scottbolen/cyber-threat-intelligence-cti-report-cve-2023-20118-cisco-small-business-routers-remote-code-185980e9e8e6"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-20118","technique":"T1505.003","technique_name_at_mapping":"Web Shell","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"Cisco Small Business Router models RV016, RV042, RV042G, RV082, RV320, and RV325 perform improper validation of HTTP packet user input. An authenticated attacker can craft these requests and send them, leading to arbitrary command execution.","references":["https://medium.com/@scottbolen/cyber-threat-intelligence-cti-report-cve-2023-20118-cisco-small-business-routers-remote-code-185980e9e8e6"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1068","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Privilege Escalation","name_at_mapping":"Exploitation for Privilege Escalation","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":31,"has_detection_strategy":true},{"id":"T1078","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Valid Accounts","name_at_mapping":"Valid Accounts","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":56,"has_detection_strategy":true},{"id":"T1505.003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Web Shell","name_at_mapping":"Web Shell","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":35,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}