← All CVEs

CVE-2019-1653

high · 7.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-03Remediation due 2022-05-03

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.

7.5
CVSS
99.9%
EPSS (exploit prob.)
100th
EPSS percentile
2019-01-24
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-284

Affected products

VendorProductAffected versions
ciscorv320_firmware1.4.2.15
ciscorv320_firmware1.4.2.17
ciscorv320all versions
ciscorv325_firmware1.4.2.15
ciscorv325_firmware1.4.2.17
ciscorv325all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-1653