Command injection in Small Business RV325 Dual Gigabit WAN VPN Router and Small Business RV320 Dual Gigabit WAN VPN Router - CVE-2019-1652

 

Command injection in Small Business RV325 Dual Gigabit WAN VPN Router and Small Business RV320 Dual Gigabit WAN VPN Router - CVE-2019-1652

Published: January 24, 2019 / Updated: March 8, 2022


Vulnerability identifier: #VU17195
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1652
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote authenticated attacker to execute arbitrary commands.

The vulnerability exists due to improper validation of user-supplied input. A remote attacker can send malicious HTTP POST requests to the web-based management interface and execute arbitrary commands on the underlying Linux shell as root.


Affected software

Small Business RV325 Dual Gigabit WAN VPN Router
Small Business RV320 Dual Gigabit WAN VPN Router

How to mitigate CVE-2019-1652

Update the affected firmware to version 1.4.2.20.

Small Business RV325 Dual Gigabit WAN VPN Router - update to 1.4.2.20
Small Business RV320 Dual Gigabit WAN VPN Router - update to 1.4.2.20

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins