EXPOSURES › CVE-2019-1653
CVE-2019-1653
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco Small Business RV320 and RV325 routers suffered an information disclosure flaw allowing attackers to download router configurations and diagnostic data.
The vulnerability stems from improper access controls on URL endpoints, enabling unauthorized extraction of sensitive configuration and diagnostic information. For DIB organizations, this means network topology and security settings could be exposed, aiding lateral movement or targeted attacks. Organizations must ensure these routers are patched or replaced, as the flaw is actively exploited in the wild.
Shame score — The flaw was actively exploited in the wild (KEV) and allowed attackers to exfiltrate sensitive configuration data, indicating a failure in access control design and patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.
"Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information."
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |