OS Command Injection in Cisco Systems, Inc products - CVE-2023-20118
Published: February 25, 2025 / Updated: March 3, 2025
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the web-based management interface. A remote authenticated user can a specially crafted HTTP request and execute arbitrary OS commands with root privileges.
Affected software
Cisco RV042 Dual WAN VPN Router
Cisco RV042G Dual Gigabit WAN VPN Router
Cisco RV082 Dual WAN VPN Router