CVE-2019-1653
published 2019-01-24CVE-2019-1653: A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated…
PriorityP190high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.88%
100.0th percentile
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | rv320_firmware | — | — |
| cisco | rv320_firmware | — | — |
| cisco | rv325_firmware | — | — |
| cisco | rv325_firmware | — | — |
| cisco | small_business_rv320_and_rv325_routers | — | — |
| maipu | mp1800x-50_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Alert on POST requests to /certificate_handle2.htm with a 'common_name' parameter containing shell metacharacters (e.g., $(...)) — this is the command injection delivery point used in the chained RCE exploit. ↗
- →Flag inbound HTTP traffic on port 8007 targeting Cisco RV320/RV325 management interfaces — older firmware versions expose the web management interface on this non-standard port. ↗
- →Scan internet-facing Cisco RV320/RV325 devices for firmware versions 1.4.2.15 through 1.4.2.19 (for CVE-2019-1653) — devices on these versions are vulnerable to unauthenticated config download. ↗
- ·The initial Cisco patch (firmware 1.4.2.19 for CVE-2019-1653) was confirmed incomplete by RedTeam Pentesting GmbH; over 8,000 devices remained vulnerable after patching. Full remediation requires firmware 1.4.2.22. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g8v7-mxw8-c8q8: The web interface of Maipu MP1800X-50 7
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2020-13896 [HIGH] CWE-200 GHSA-g8v7-mxw8-c8q8: The web interface of Maipu MP1800X-50 7
The web interface of Maipu MP1800X-50 7.5.3.14(R) devices allows remote attackers to obtain sensitive information via the form/formDeviceVerGet URI, such as system id, hardware model, hardware version, bootloader version, software version, software image file, compilation time, and system uptime. This is similar to CVE-2019-1653.
GHSA
GHSA-j8w2-wx5p-fvx4: A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthentica
ghsa_unreviewed·2022-05-13
CVE-2019-1653 [HIGH] CWE-200 GHSA-j8w2-wx5p-fvx4: A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthentica
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.
VulnCheck
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
vulncheck·2019·CVSS 7.5
CVE-2019-1653 [HIGH] CWE-284 Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.
Affected: Cisco RV Series Routers
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.mandiant.com/resources/blog/apt41-initiates-global-intrusion-campaign-using-multiple-exploits; https://www.justice.gov/opa/pr/seven-international-cyber-defendants-including-apt41-actors-charged-connection-computer; https://www.bleepingcomputer.com/news/security/us-charges-chinese-winnti-hackers-for-attacking-100-plus-companies/; https://cisa.gov/news-events/cybersec
CISA
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
cisa·2021-11-03·CVSS 7.5
CVE-2019-1653 [HIGH] CWE-284 Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
Vulnerability: Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
Affected: Cisco Small Business RV320 and RV325 Routers
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1653
Remediation Due Date: 2022-05-03
Cisco
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
vendor_cisco·2019-01-23·CVSS 7.5
CVE-2019-1653 [HIGH] CWE-200 Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information.
The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information.
Update, April 4, 2019: The initial fix for this vulnerability was found to be incomplete. The complete fix is now available in Firmware Release 1.4.2.22.
Firmware updates that address this vulnerabili
Cisco
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1653 Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
CVE-2019-1653: Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Update, April 4, 2019: The initial fix for this vulnerability was found to be incomplete. The complete fix is now available in Firmware Release 1.4.2.22. Firmware updates that address th
Suricata
ET EXPLOIT Cisco RV320/RV325 RCE (CVE-2019-1653)
suricata·2021-10-28·CVSS 7.5
CVE-2019-1653 [HIGH] ET EXPLOIT Cisco RV320/RV325 RCE (CVE-2019-1653)
ET EXPLOIT Cisco RV320/RV325 RCE (CVE-2019-1653)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Cisco RV320/RV325 RCE (CVE-2019-1653)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"certificate_handle2.htm"; nocase; fast_pattern; http.request_body; content:"page=self_generator.htm"; nocase; content:"common_name="; pcre:"/[^\r\n]*(?:\x60|\x24|\x7c|\bsh\b)/Ri"; reference:url,www.redteam-pentesting.de/en/advisories/rt-sa-2018-004/-cisco-rv320-command-injection; reference:cve,2019-1653; classtype:attempted-admin; sid:2034278; rev:1; metadata:attack_target Networking_Equipment, created_at 2021_10_28, cve CVE_2019_1653, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2021_1
Suricata
ET EXPLOIT Successful Cisco RV320/RV325 Debug Dump Disclosure (CVE-2019-1653)
suricata·2021-06-04·CVSS 7.5
CVE-2019-1653 [HIGH] ET EXPLOIT Successful Cisco RV320/RV325 Debug Dump Disclosure (CVE-2019-1653)
ET EXPLOIT Successful Cisco RV320/RV325 Debug Dump Disclosure (CVE-2019-1653)
Rule: alert http $HOME_NET any -> any any (msg:"ET EXPLOIT Successful Cisco RV320/RV325 Debug Dump Disclosure (CVE-2019-1653)"; flow:established,to_client; flowbits:isset,ET.cve20191653.2; file.data; content:"Salted__"; reference:url,github.com/0x27/CiscoRV320Dump; reference:cve,2019-1653; classtype:attempted-admin; sid:2033092; rev:3; metadata:attack_target Networking_Equipment, created_at 2021_06_04, cve CVE_2019_1653, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_14;)
Suricata
ET EXPLOIT Successful Cisco RV320/RV325 Config Disclosure (CVE-2019-1653)
suricata·2021-06-04·CVSS 7.5
CVE-2019-1653 [HIGH] ET EXPLOIT Successful Cisco RV320/RV325 Config Disclosure (CVE-2019-1653)
ET EXPLOIT Successful Cisco RV320/RV325 Config Disclosure (CVE-2019-1653)
Rule: alert http $HOME_NET any -> any any (msg:"ET EXPLOIT Successful Cisco RV320/RV325 Config Disclosure (CVE-2019-1653)"; flow:established,to_client; flowbits:isset,ET.cve20191653.1; file.data; content:"sysconfig"; reference:url,github.com/0x27/CiscoRV320Dump; reference:cve,2019-1653; classtype:attempted-admin; sid:2033090; rev:3; metadata:attack_target Networking_Equipment, created_at 2021_06_04, cve CVE_2019_1653, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_14;)
Suricata
ET EXPLOIT Cisco RV320/RV325 Config Disclosure Attempt Inbound (CVE-2019-1653)
suricata·2021-06-04·CVSS 7.5
CVE-2019-1653 [HIGH] ET EXPLOIT Cisco RV320/RV325 Config Disclosure Attempt Inbound (CVE-2019-1653)
ET EXPLOIT Cisco RV320/RV325 Config Disclosure Attempt Inbound (CVE-2019-1653)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Cisco RV320/RV325 Config Disclosure Attempt Inbound (CVE-2019-1653)"; flow:established,to_server; flowbits:set,ET.cve20191653.1; http.method; content:"GET"; http.uri; content:"/cgi-bin/config.exp"; endswith; fast_pattern; reference:url,github.com/0x27/CiscoRV320Dump; reference:cve,2019-1653; classtype:attempted-admin; sid:2033089; rev:2; metadata:attack_target Networking_Equipment, created_at 2021_06_04, cve CVE_2019_1653, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_14;)
Suricata
ET EXPLOIT Cisco RV320/RV325 Debug Dump Disclosure Attempt Inbound (CVE-2019-1653)
suricata·2021-06-04·CVSS 7.5
CVE-2019-1653 [HIGH] ET EXPLOIT Cisco RV320/RV325 Debug Dump Disclosure Attempt Inbound (CVE-2019-1653)
ET EXPLOIT Cisco RV320/RV325 Debug Dump Disclosure Attempt Inbound (CVE-2019-1653)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Cisco RV320/RV325 Debug Dump Disclosure Attempt Inbound (CVE-2019-1653)"; flow:established,to_server; flowbits:set,ET.cve20191653.2; http.method; content:"POST"; http.uri; content:"/cgi-bin/export_debug_msg.exp"; endswith; fast_pattern; http.request_body; content:"submitdebugmsg|22 3a 20 22|1|22|"; reference:url,github.com/0x27/CiscoRV320Dump; reference:cve,2019-1653; classtype:attempted-admin; sid:2033091; rev:2; metadata:attack_target Networking_Equipment, created_at 2021_06_04, cve CVE_2019_1653, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_14;)
Exploit-DB
Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
exploitdb·2019-04-03·CVSS 7.2
CVE-2019-1653 [HIGH] Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule "Cisco RV320 and RV325 Unauthenticated Remote Code Execution",
'Description' => %q{
This exploit module combines an information disclosure (CVE-2019-1653)
and a command injection vulnerability (CVE-2019-1652) together to gain
unauthenticated remote code execution on Cisco RV320 and RV325 small business
routers. Can be exploited via the WAN interface of the router. Either via HTTPS
on port 443 or HTTP on port 8007 on some older firmware versions.
},
'License' => MSF_LICENSE,
'Author' => [
'RedTeam Pentesting GmbH', # Discovery, Metasploit
'Philip Huppe
Exploit-DB
Cisco RV300 / RV320 - Information Disclosure
exploitdb·2019-01-28·CVSS 7.5
CVE-2019-1653 [HIGH] Cisco RV300 / RV320 - Information Disclosure
Cisco RV300 / RV320 - Information Disclosure
---
# Exploit Title: 6coRV Exploit
# Date: 01-26-2018
# Exploit Author: Harom Ramos [Horus]
# Tested on: Cisco RV300/RV320
# CVE : CVE-2019-1653
import requests
from requests.packages.urllib3.exceptions import InsecureRequestWarning
from fake_useragent import UserAgent
def random_headers():
return dict({'user-agent': UserAgent().random})
def request(url):
r = requests.Session()
try:
get = r.get(url, headers = random_headers(), timeout = 5, verify=False)#, allow_redirects=False
if get.status_code == 200:
return get.text
except requests.ConnectionError:
return 'Error Conecting'
except requests.Timeout:
return 'Error Timeout'
except KeyboardInterrupt:
raise
except:
return 0
print("")
print("##################################################")
Metasploit
Cisco RV320/RV326 Configuration Disclosure
metasploit
Cisco RV320/RV326 Configuration Disclosure
Cisco RV320/RV326 Configuration Disclosure
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.
Metasploit
Cisco RV320 and RV325 Unauthenticated Remote Code Execution
metasploit·CVSS 7.2
CVE-2019-1653 [HIGH] Cisco RV320 and RV325 Unauthenticated Remote Code Execution
Cisco RV320 and RV325 Unauthenticated Remote Code Execution
This exploit module combines an information disclosure (CVE-2019-1653) and a command injection vulnerability (CVE-2019-1652) together to gain unauthenticated remote code execution on Cisco RV320 and RV325 small business routers. Can be exploited via the WAN interface of the router. Either via HTTPS on port 443 or HTTP on port 8007 on some older firmware versions.
Nuclei
Cisco Small Business WAN VPN Routers - Sensitive Information Disclosure
nuclei·CVSS 7.5
CVE-2019-1653 [HIGH] Cisco Small Business WAN VPN Routers - Sensitive Information Disclosure
Cisco Small Business WAN VPN Routers - Sensitive Information Disclosure
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated remote attacker to retrieve sensitive information due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information.
Template:
id: CVE-2019-1653
info:
name: Cisco Small Business WAN VPN Routers - Sensitive Information Disclosure
author: dwisiswant0
severity: high
description: |
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated remote attacker to retrieve
Nuclei
PilusCart <=1.4.1 - Local File Inclusion
nuclei·CVSS 7.5
CVE-2019-16123 [HIGH] PilusCart <=1.4.1 - Local File Inclusion
PilusCart =1.4.2) or apply the vendor-supplied patch to mitigate the LFI vulnerability.
reference:
- https://packetstormsecurity.com/files/154250/PilusCart-1.4.1-Local-File-Disclosure.html
- https://www.exploit-db.com/exploits/47315
- https://nvd.nist.gov/vuln/detail/CVE-2019-1653
- https://zerodays.lol/
- https://github.com/ARPSyndicate/kenzer-templates
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2019-16123
cwe-id: CWE-22
epss-score: 0.47663
epss-percentile: 0.97711
cpe: cpe:2.3:a:kartatopia:piluscart:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: kartatopia
product: piluscart
tags: cve,cve2019,piluscart,lfi,packetstorm,edb,kartatopia,vuln
http:
- method: GET
path:
- "{{BaseURL}}/catalog.php?filename=../../../../../../../../../
Qualys
Russia-Ukraine Crisis: How to Strengthen Your Security Posture to Protect against Cyber Attack, based on CISA Guidelines
blogs_qualys·2022-02-26
Russia-Ukraine Crisis: How to Strengthen Your Security Posture to Protect against Cyber Attack, based on CISA Guidelines
## Table of Contents
Protecting Customer Data on Qualys Cloud Platform
Urgent: Assess and Heighten Your Security Posture
Step 1: Monitor Your Shodan/Internet Exposed Assets
Step 2: Detect, Prioritize and Remediate CISAs Catalog ofKnown Exploited Vulnerabilities
Step 3: Protect Your Cloud Services and Office 365
Step 4: Continuously Detect any Potential Threats and Attacks
Take Action to Learn More about How to Strengthen Your Defenses
CISA has created Shields Up as a response to the Russian invasion of Ukraine. Qualys is responding with additional security, monitoring and governance measures. This blog details how and what our enterprise customers can do to immediately strengthen their security posture and meet CISA’s recommendations.
With the invasion of Ukraine by Russia, the U.
Tenable
Government Advisories Warn of APT Activity Resulting from Russian Invasion of Ukraine
blogs_tenable·2022-02-24
Government Advisories Warn of APT Activity Resulting from Russian Invasion of Ukraine
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Unit42
Russia-Ukraine Cyberattacks (Updated): How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon, Website Defacement, Phishing and Scams
blogs_unit42·2022-02-22
Russia-Ukraine Cyberattacks (Updated): How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon, Website Defacement, Phishing and Scams
Threat Research Center
Threat Research
Malware
## Russia-Ukraine Cyberattacks (Updated): How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon, Website Defacement, Phishing and Scams
Unit 42
Published: February 22, 2022
Malware
Threat Research
DDoS
Defacement
Gamaredon
HermeticWiper
Nation-state
Russia
Trident Ursa
Ukraine
WhisperGate
## Executive Summary
Over the past several weeks, Russia-Ukraine cyber activity has escalated substantially. Beginning on Feb. 15, a series of distributed denial of service (DDoS) attacks commenced. These attacks have continued over the past week, impacting both the Ukrainian government and banking institutions. On Feb. 23, a new variant of wiper malware named HermeticWiper was discovered in Ukraine. Shortl
Unit42
Russia-Ukraine Cyberattacks (Updated): How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon, Website Defacement, Phishing and Scams
blogs_unit42·2022-02-22
Russia-Ukraine Cyberattacks (Updated): How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon, Website Defacement, Phishing and Scams
## Executive Summary
Over the past several weeks, Russia-Ukraine cyber activity has escalated substantially. Beginning on Feb. 15, a series of distributed denial of service (DDoS) attacks commenced. These attacks have continued over the past week, impacting both the Ukrainian government and banking institutions. On Feb. 23, a new variant of wiper malware named HermeticWiper was discovered in Ukraine. Shortly after, a new round of website defacement attacks were also observed impacting Ukrainian government organizations.
Consistent with our previous reporting on the topic, several western governments have issued recommendations for their populations to prepare for cyberattacks that could disrupt, disable or destroy critical infrastructure. We have already observed an increase in Russian c
Tenable
Cisco Fixes Incomplete Patch for RV320 and RV325 Routers, Including Two New Bugs (CVE-2019-1827, CVE-2019-1828)
blogs_tenable·2019-04-04·CVSS 6.1
[MEDIUM] Cisco Fixes Incomplete Patch for RV320 and RV325 Routers, Including Two New Bugs (CVE-2019-1827, CVE-2019-1828)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cisco Fixes Incomplete Patch for RV320 and RV325 Routers, Including Two New Bugs (CVE-2019-1827, CVE-2019-1828)
blogs_tenable·2019-04-04·CVSS 7.2
CVE-2019-1827 [HIGH] Cisco Fixes Incomplete Patch for RV320 and RV325 Routers, Including Two New Bugs (CVE-2019-1827, CVE-2019-1828)
Blog / Cyber Exposure Alerts
Subscribe
# Cisco Fixes Incomplete Patch for RV320 and RV325 Routers, Including Two New Bugs (CVE-2019-1827, CVE-2019-1828)
Satnam Narang
April 4, 2019
3 Min Read
Cisco finalizes patch for RV320 and RV325 after researchers determined a previous patch was incomplete.
### Background
On April 4, Cisco published updated advisories to address two vulnerabilities in its RV320 and RV325 routers that were originally reported in January 2019. Additionally, Cisco published advisories for two newly discovered, medium severity bugs in the same routers.
### Analysis
Tenable blogged about these vulnerabilities -- CVE-2019-1652 and CVE-2019-1653 -- in late January when public exploit scripts were published. Shortly after publication, reports about exploit attempts ag
Tenable
Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
blogs_tenable·2019-01-25·CVSS 7.2
[HIGH] Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
Blog / Cyber Exposure Alerts
Subscribe
# Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
Satnam Narang
January 25, 2019
3 Min Read
Availability of public exploit scripts for two vulnerabilities in Cisco Small Business WAN VPN routers coupled with incoming scans for vulnerable devices indicate that attackers are preparing to launch attacks.
### Background
On January 23, Cisco published a list of security advisories including advisories for two vulnerabilities in Cisco Small Business RV320 and RV325 dual gigabit WAN VPN routers. Both vulnerabilities exist within the routers’ web-based management interface. The first is CVE-2019-1652, a command injection vulnerability that exists in firmware versions 1.4.2.15 through 1.4.2.19. The second
Tenable
Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
blogs_tenable·2019-01-25
Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://packetstormsecurity.com/files/152260/Cisco-RV320-Unauthenticated-Configuration-Export.htmlhttp://packetstormsecurity.com/files/152261/Cisco-RV320-Unauthenticated-Diagnostic-Data-Retrieval.htmlhttp://packetstormsecurity.com/files/152305/Cisco-RV320-RV325-Unauthenticated-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2019/Mar/59http://seclists.org/fulldisclosure/2019/Mar/60http://www.securityfocus.com/bid/106732https://badpackets.net/over-9000-cisco-rv320-rv325-routers-vulnerable-to-cve-2019-1653/https://seclists.org/bugtraq/2019/Mar/53https://seclists.org/bugtraq/2019/Mar/54https://threatpost.com/scans-cisco-routers-code-execution/141218/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-infohttps://www.exploit-db.com/exploits/46262/https://www.exploit-db.com/exploits/46655/https://www.youtube.com/watch?v=bx0RQJDlGbYhttps://www.zdnet.com/article/hackers-are-going-after-cisco-rv320rv325-routers-using-a-new-exploit/http://packetstormsecurity.com/files/152260/Cisco-RV320-Unauthenticated-Configuration-Export.htmlhttp://packetstormsecurity.com/files/152261/Cisco-RV320-Unauthenticated-Diagnostic-Data-Retrieval.htmlhttp://packetstormsecurity.com/files/152305/Cisco-RV320-RV325-Unauthenticated-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2019/Mar/59http://seclists.org/fulldisclosure/2019/Mar/60http://www.securityfocus.com/bid/106732https://badpackets.net/over-9000-cisco-rv320-rv325-routers-vulnerable-to-cve-2019-1653/https://seclists.org/bugtraq/2019/Mar/53https://seclists.org/bugtraq/2019/Mar/54https://threatpost.com/scans-cisco-routers-code-execution/141218/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-infohttps://www.exploit-db.com/exploits/46262/https://www.exploit-db.com/exploits/46655/https://www.youtube.com/watch?v=bx0RQJDlGbYhttps://www.zdnet.com/article/hackers-are-going-after-cisco-rv320rv325-routers-using-a-new-exploit/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1653
2019-01-24
Published
2021-11-03
Added to CISA KEV
Exploited in the wild