Information disclosure in Small Business RV325 Dual Gigabit WAN VPN Router and Small Business RV320 Dual Gigabit WAN VPN Router - CVE-2019-1653
Published: January 23, 2019 / Updated: October 9, 2021
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to improper access controls for URLs. A remote attacker can connect to an affected device via HTTP or HTTPS and requesting specific URLs to download the router configuration or detailed diagnostic information.
Affected software
Small Business RV320 Dual Gigabit WAN VPN Router
How to mitigate CVE-2019-1653
Small Business RV320 Dual Gigabit WAN VPN Router - update to 1.4.2.19
Links to Public Exploits and PoC-codes
- Exploit #6027 - Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit) (June 17, 2021)
- Exploit #5957 - Cisco RV300 / RV320 - Information Disclosure (June 17, 2021)
- Exploit #1976 - CiscoRV320Dump (CVE-2019-1652 /CVE-2019-1653 Exploits For Dumping Cisco RV320 Configurations & Debugging Data AND Remote Root Exploit!) (March 18, 2020)
- Exploit #2006 - CiscoSpill (Just a PoC tool to extract password using CVE-2019-1653.) (March 18, 2020)
- Exploit #87 - Cisco RV320/RV326 Configuration Disclosure (March 18, 2020)
- Exploit #229 - CiscoExploit (Cisco Exploit (CVE-2019-1821 Cisco Prime Infrastructure Remote Code Execution/CVE-2019-1653/Cisco SNMP RCE/Dump Cisco RV320 Password)) (March 18, 2020)
- Exploit #1573 - Cisco RV320 and RV325 Unauthenticated Remote Code Execution (March 18, 2020)