EXPOSURES › CVE-2019-1652
CVE-2019-1652
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco Small Business RV320/RV325 routers had an improper input validation flaw allowing authenticated remote attackers to execute arbitrary commands.
The web-based management interface of Cisco Small Business RV320 and RV325 routers suffered from improper input validation, enabling authenticated remote attackers with administrative privileges to execute arbitrary commands. DIB organizations must care because this RCE flaw, listed in CISA's KEV catalog, indicates a known, actively exploited vulnerability that could compromise network integrity and violate CMMC/NIST 800-171 controls if unpatched. Organizations should immediately verify patch levels on all legacy Cisco Small Business routers and replace them with hardened alternatives.
Shame score — A known, actively exploited RCE vulnerability in widely deployed small business routers demonstrates negligent security development and prolonged exposure to active exploitation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |