Command injection in Small Business RV325 Dual Gigabit WAN VPN Router and Small Business RV320 Dual Gigabit WAN VPN Router - CVE-2019-1652
Published: January 24, 2019 / Updated: March 8, 2022
Vulnerability details
The vulnerability allows a remote authenticated attacker to execute arbitrary commands.
The vulnerability exists due to improper validation of user-supplied input. A remote attacker can send malicious HTTP POST requests to the web-based management interface and execute arbitrary commands on the underlying Linux shell as root.
Affected software
Small Business RV320 Dual Gigabit WAN VPN Router
How to mitigate CVE-2019-1652
Small Business RV320 Dual Gigabit WAN VPN Router - update to 1.4.2.20
Links to Public Exploits and PoC-codes
- Exploit #6026 - Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit) (June 17, 2021)
- Exploit #5958 - Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection (June 17, 2021)
- Exploit #1977 - CiscoRV320Dump (CVE-2019-1652 /CVE-2019-1653 Exploits For Dumping Cisco RV320 Configurations & Debugging Data AND Remote Root Exploit!) (March 18, 2020)
- Exploit #2161 - CiscoExploit (Cisco Exploit (CVE-2019-1821 Cisco Prime Infrastructure Remote Code Execution/CVE-2019-1653/Cisco SNMP RCE/Dump Cisco RV320 Password)) (March 18, 2020)
- Exploit #1572 - Cisco RV320 and RV325 Unauthenticated Remote Code Execution (March 18, 2020)