CVE-2019-1653 KEV EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 99.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 99.88% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-284 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | yes |
| Published | 2019-01-24 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Cisco / Small Business RV320 and RV325 Routers |
| Ransomware use | none reported |
Affected (4)
| Vendor | Product |
|---|---|
| cisco | rv320 |
| cisco | rv320 firmware |
| cisco | rv325 |
| cisco | rv325 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit) | 2019-04-03 |
| exploit-db | Cisco RV300 / RV320 - Information Disclosure | 2019-01-28 |
References
- http://packetstormsecurity.com/files/152260/Cisco-RV320-Unauthenticated-Configuration-Export.html
- http://packetstormsecurity.com/files/152261/Cisco-RV320-Unauthenticated-Diagnostic-Data-Retrieval.html
- http://packetstormsecurity.com/files/152305/Cisco-RV320-RV325-Unauthenticated-Remote-Code-Execution.html
- http://seclists.org/fulldisclosure/2019/Mar/59
- http://seclists.org/fulldisclosure/2019/Mar/60
- http://www.securityfocus.com/bid/106732
- https://badpackets.net/over-9000-cisco-rv320-rv325-routers-vulnerable-to-cve-2019-1653/
- https://seclists.org/bugtraq/2019/Mar/53
- https://seclists.org/bugtraq/2019/Mar/54
- https://threatpost.com/scans-cisco-routers-code-execution/141218/
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-info
- https://www.exploit-db.com/exploits/46262/
- https://www.exploit-db.com/exploits/46655/
- https://www.youtube.com/watch?v=bx0RQJDlGbY
- https://www.zdnet.com/article/hackers-are-going-after-cisco-rv320rv325-routers-using-a-new-exploit/
- http://packetstormsecurity.com/files/152260/Cisco-RV320-Unauthenticated-Configuration-Export.html
- http://packetstormsecurity.com/files/152261/Cisco-RV320-Unauthenticated-Diagnostic-Data-Retrieval.html
- http://packetstormsecurity.com/files/152305/Cisco-RV320-RV325-Unauthenticated-Remote-Code-Execution.html
- http://seclists.org/fulldisclosure/2019/Mar/59
- http://seclists.org/fulldisclosure/2019/Mar/60
→ the Explorer · watch your stack · NVD