Cisco Small Business Routers Vulnerable to Authentication Bypass and Remote Code Execution

Threat Level – Red | Vulnerability Report
Download PDF

Multiple vulnerabilities were found in the web-based management interface of Cisco Small Business Routers. The authentication bypass vulnerability (CVE-2023-20025) allows an unauthenticated attacker to bypass authentication on an affected device by manipulating user input in incoming HTTP packets. The remote command execution vulnerability (CVE-2023-20026) allows an authenticated attacker to execute arbitrary commands on an affected device by manipulating user input in incoming HTTP packets.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox