CVE-2019-1653

HIGH KEV NUCLEI

Cisco RV320 and RV325 Unauthenticated Remote Code Execution

Title source: metasploit

Description

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.

Exploits (10)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotehardware
https://www.exploit-db.com/exploits/46655
exploitdb WORKING POC
by Harom Ramos · pythonwebappshardware
https://www.exploit-db.com/exploits/46262
nomisec WORKING POC 4 stars
by shaheemirza · remote
https://github.com/shaheemirza/CiscoSpill
nomisec WORKING POC 1 stars
by ibrahimzx · remote
https://github.com/ibrahimzx/CVE-2019-1653
nomisec SCANNER 1 stars
by dubfr33 · remote
https://github.com/dubfr33/CVE-2019-1653
gitlab WORKING POC
by FiveO · poc
https://gitlab.com/FiveO/CiscoExploit
nomisec SCANNER
by elzerjp · infoleak
https://github.com/elzerjp/nuclei-CiscoRV320Dump-CVE-2019-1653
vulncheck_xdb WORKING POC
infoleak
https://github.com/0x27/CiscoRV320Dump
metasploit WORKING POC
by RedTeam Pentesting GmbH <[email protected]>, Aaron Soto <[email protected]> · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/cisco_rv320_config.rb
metasploit WORKING POC NORMAL
by RedTeam Pentesting GmbH, Philip Huppert, Benjamin Grap · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/cisco_rv32x_rce.rb

Nuclei Templates (1)

Cisco Small Business WAN VPN Routers - Sensitive Information Disclosure
HIGHby dwisiswant0

References (16)

Scores

CVSS v3 7.5
EPSS 0.9438
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-03-25
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2019-10210
CWE
CWE-284
Status published
Products (4)
cisco/rv320_firmware 1.4.2.15
cisco/rv320_firmware 1.4.2.17
cisco/rv325_firmware 1.4.2.15
cisco/rv325_firmware 1.4.2.17
Published Jan 24, 2019
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026