ID:5958 - Exploit for Command injection in Small Business RV325 Dual Gigabit WAN VPN Router and Small Business RV320 Dual Gigabit WAN VPN Router - CVE-2019-1652

 
Main Vulnerability Database Exploits ID:5958 - Exploit for Command injection in Small Business RV325 Dual Gigabit WAN VPN Router and Small Business RV320 Dual Gigabit WAN VPN Router - CVE-2019-1652

ID:5958 - Exploit for Command injection in Small Business RV325 Dual Gigabit WAN VPN Router and Small Business RV320 Dual Gigabit WAN VPN Router - CVE-2019-1652

Published: June 17, 2021


Vulnerability identifier: #VU17195
Vulnerability risk: Low
CVE-ID: CVE-2019-1652
CWE-ID: CWE-77
Exploitation vector: Remote access
Vulnerable software:
Small Business RV325 Dual Gigabit WAN VPN Router
Small Business RV320 Dual Gigabit WAN VPN Router

Link to public exploit:


Vulnerability description

The vulnerability allows a remote authenticated attacker to execute arbitrary commands.

The vulnerability exists due to improper validation of user-supplied input. A remote attacker can send malicious HTTP POST requests to the web-based management interface and execute arbitrary commands on the underlying Linux shell as root.


Remediation

Update the affected firmware to version 1.4.2.20.