Medium
CVE-2023-20045
Small Business RV160 and RV260 Series VPN Routers could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by improper validation of user input. By sending a specially-crafted request to the web-based management interface, an attacker could exploit this vulnerability to execute arbitrary commands using root-level privileges on the device.
Cisco
Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.