#VU17195 Command injection in Small Business RV325 Dual Gigabit WAN VPN Router and Small Business RV320 Dual Gigabit WAN VPN Router - CVE-2019-1652
Published: January 24, 2019 / Updated: March 8, 2022
Small Business RV325 Dual Gigabit WAN VPN Router
Small Business RV320 Dual Gigabit WAN VPN Router
Cisco Systems, Inc
Description
The vulnerability allows a remote authenticated attacker to execute arbitrary commands.
The vulnerability exists due to improper validation of user-supplied input. A remote attacker can send malicious HTTP POST requests to the web-based management interface and execute arbitrary commands on the underlying Linux shell as root.