PT-2019-1227 · Cisco · Cisco Small Business Rv325+1

Published

2019-01-23

·

Updated

2026-03-10

·

CVE-2019-1653

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers (affected versions not specified)
Description A vulnerability in the web-based management interface of the routers could allow an unauthenticated, remote attacker to retrieve sensitive information due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs, potentially allowing them to download the router configuration or detailed diagnostic information.
Recommendations For Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers, update to the latest firmware version released by Cisco to address this vulnerability. As a temporary workaround, consider restricting access to the web-based management interface until a patch is applied. Avoid using HTTP or HTTPS to connect to the device until the issue is resolved, if possible. At the moment, there is no information about specific steps to mitigate the vulnerability beyond updating the firmware.

Exploit

Fix

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2019-00340
CVE-2019-1653

Affected Products

Cisco Small Business Rv320
Cisco Small Business Rv325