Security News > 2022 > August > Cisco Business Routers Found Vulnerable to Critical Remote Hacking Flaws
![Cisco Business Routers Found Vulnerable to Critical Remote Hacking Flaws](/static/build/img/news/cisco-business-routers-found-vulnerable-to-critical-remote-hacking-flaws-medium.jpg)
Cisco on Wednesday rolled out patches to address eight security vulnerabilities, three of which could be weaponized by an unauthenticated attacker to gain remote code execution or cause a denial-of-service condition on affected devices.
The most critical of the flaws impact Cisco Small Business RV160, RV260, RV340, and RV345 Series routers.
"An attacker could exploit this vulnerability by sending crafted HTTP input to an affected device," Cisco said in an advisory.
"A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a DoS condition."
A second shortcoming relates to a command injection vulnerability residing in the routers' web filter database update feature, which could be exploited by an adversary to inject and execute arbitrary commands on the underlying operating system with root privileges.
The company offered no workarounds to remediate the issues, adding there is no evidence of these vulnerabilities being exploited in the wild.
News URL
https://thehackernews.com/2022/08/cisco-business-routers-found-vulnerable.html
Related news
- BeyondTrust fixes critical vulnerability in remote access, support solutions (CVE-2024-12356) (source)
- Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools (source)
- Sophos Firewall vulnerable to critical remote code execution flaw (source)
- Sophos discloses critical Firewall remote code execution flaw (source)
- Critical RCE Flaw in GFI KerioControl Allows Remote Code Execution via CRLF Injection (source)
- Cisco Fixes Critical Privilege Escalation Flaw in Meeting Management (CVSS 9.9) (source)
- Cisco fixes ClamAV vulnerability with available PoC and critical Meeting Management flaw (source)
- Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management (source)
- Critical Cacti Security Flaw (CVE-2025-22604) Enables Remote Code Execution (source)
- Netgear warns users to patch critical WiFi router vulnerabilities (source)