Main
Vulnerability Database
Exploits
ID:5958 - Exploit for Command injection in Small Business RV325 Dual Gigabit WAN VPN Router and Small Business RV320 Dual Gigabit WAN VPN Router - CVE-2019-1652
ID:5958 - Exploit for Command injection in Small Business RV325 Dual Gigabit WAN VPN Router and Small Business RV320 Dual Gigabit WAN VPN Router - CVE-2019-1652
Published: June 17, 2021
Vulnerability identifier: #VU17195
Vulnerability risk: Low
CVE-ID: CVE-2019-1652
CWE-ID: CWE-77
Exploitation vector: Remote access
Vulnerable software:
Small Business RV325 Dual Gigabit WAN VPN Router
Small Business RV320 Dual Gigabit WAN VPN Router
Small Business RV325 Dual Gigabit WAN VPN Router
Small Business RV320 Dual Gigabit WAN VPN Router
Link to public exploit:
Vulnerability description
The vulnerability allows a remote authenticated attacker to execute arbitrary commands.
The vulnerability exists due to improper validation of user-supplied input. A remote attacker can send malicious HTTP POST requests to the web-based management interface and execute arbitrary commands on the underlying Linux shell as root.
Remediation
Update the affected firmware to version 1.4.2.20.