PT-2019-1227 · Cisco · Cisco Small Business Rv325+1
Published
2019-01-23
·
Updated
2026-03-10
·
CVE-2019-1653
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers (affected versions not specified)
Description
A vulnerability in the web-based management interface of the routers could allow an unauthenticated, remote attacker to retrieve sensitive information due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs, potentially allowing them to download the router configuration or detailed diagnostic information.
Recommendations
For Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers, update to the latest firmware version released by Cisco to address this vulnerability.
As a temporary workaround, consider restricting access to the web-based management interface until a patch is applied.
Avoid using HTTP or HTTPS to connect to the device until the issue is resolved, if possible.
At the moment, there is no information about specific steps to mitigate the vulnerability beyond updating the firmware.
Exploit
Fix
Improper Access Control
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Small Business Rv320
Cisco Small Business Rv325