Information disclosure in Small Business RV325 Dual Gigabit WAN VPN Router and Small Business RV320 Dual Gigabit WAN VPN Router - CVE-2019-1653

 

Information disclosure in Small Business RV325 Dual Gigabit WAN VPN Router and Small Business RV320 Dual Gigabit WAN VPN Router - CVE-2019-1653

Published: January 23, 2019 / Updated: October 9, 2021


Vulnerability identifier: #VU17194
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1653
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists due to improper access controls for URLs. A remote attacker can connect to an affected device via HTTP or HTTPS and requesting specific URLs  to download the router configuration or detailed diagnostic information.


Affected software

Small Business RV325 Dual Gigabit WAN VPN Router
Small Business RV320 Dual Gigabit WAN VPN Router

How to mitigate CVE-2019-1653

Update the affected firmware to version 1.4.2.19.

Small Business RV325 Dual Gigabit WAN VPN Router - update to 1.4.2.19
Small Business RV320 Dual Gigabit WAN VPN Router - update to 1.4.2.19

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins