Cisco’s RV Routers: End of Life and End of Security

Share This Post

Cisco has announced that it will not be releasing patches for a critical vulnerability (CVE-2023-20025) that affects small business RV016, RV042, RV042G, and RV082 routers, as they have reached end of life. The vulnerability, which has a CVSS score of 9.0, impacts the web-based management interface of the routers and could be exploited to bypass authentication. The issue exists because user input within incoming HTTP packets is not properly validated, allowing an attacker to send crafted HTTP requests to the router, to bypass authentication and gain root access to the operating system. Cisco also warned of a high-severity bug in the web-based management interface of the same routers, which could lead to remote command execution (CVE-2023-20026), but this vulnerability requires the attacker to be authenticated. To mitigate these vulnerabilities, administrators can disable remote management on the affected devices and block access to ports 443 and 60443. Cisco says it is not aware of any malicious attacks targeting the vulnerabilities.

Links:

https://www.securityweek.com/cisco-warns-critical-vulnerability-eol-small-business-routers

https://www.helpnetsecurity.com/2023/01/12/cve-2023-20025-cve-2023-20026/



Reach out to our incident response team for help

More To Explore

Information Security News – 5/12/2025

Microsoft Sets Passkeys Default for New Accounts Article Link: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html Accenture: What We Learned When Our CEO Got Deepfaked Article Link: https://www.computing.co.uk/event/2025/accenture-what-we-learned-when-our-ceo-got-deepfaked Ghost Students Creating

Information Security News – 5/5/2025

Cloudflare Sees a Big Jump in DDoS Attacks Article Link: https://www.bleepingcomputer.com/news/security/cloudflare-mitigates-record-number-of-ddos-attacks-in-2025/ Bring Your Own Computer Trend Gives Cyber Pros Chills, Yet It’s Here to Stay

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.