CVE-2019-1653: Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.
Other sources
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-1653?
CVE-2019-1653 is a vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers.
How does CVE-2019-1653 affect Cisco Small Business RV320 and RV325 Routers?
CVE-2019-1653 allows an unauthenticated, remote attacker to retrieve sensitive information due to improper access controls for URLs.
What is the severity of CVE-2019-1653?
CVE-2019-1653 has a severity score of 7.5 (high).
How can I fix CVE-2019-1653?
To fix CVE-2019-1653, Cisco has released firmware updates for the affected routers. It is recommended to update to the latest firmware version.
Where can I find more information about CVE-2019-1653?
You can find more information about CVE-2019-1653 on the following references: [Reference 1](http://packetstormsecurity.com/files/152260/Cisco-RV320-Unauthenticated-Configuration-Export.html), [Reference 2](http://packetstormsecurity.com/files/152261/Cisco-RV320-Unauthenticated-Diagnostic-Data-Retrieval.html), [Reference 3](http://packetstormsecurity.com/files/152305/Cisco-RV320-RV325-Unauthenticated-Remote-Code-Execution.html).