Medium
CVE-2022-20880
Multiple Cisco Small Business routers could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by insufficient validation of user fields within incoming HTTP packets. By sending a specially-crafted request to the web-based management interface, an attacker could exploit this vulnerability to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart.
CVE-2022-20881
Multiple Cisco Small Business routers could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by insufficient validation of user fields within incoming HTTP packets. By sending a specially-crafted request to the web-based management interface, an attacker could exploit this vulnerability to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart.
Cisco
Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.