VDB

CVE-2019-1652

CVE-2019-1652 PUBLISHED KEV CVSS 7.199999809265137 HIGH

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root. Cisco has released firmware updates that address this vulnerability.

EPSS 92.73% · 99.8th percentile

Risk Scores

CVSS 3.0
7.199999809265137
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
92.73%
99.8th percentile

Affected Products

VendorProductVersions
ciscorv325_firmware1.4.2.15, 1.4.2.15, 1.4.2.15
CiscoCisco Small Business RV Series Router Firmwaren/a
CiscoCisco Identity Services Engine Softwaren/a
ciscorv320_firmware1.4.2.15, 1.4.2.15, 1.4.2.15

Timeline

  • Jan 18, 1970 VulnCheck XDB Entry
  • Jan 23, 2019 CVE Published
  • Jan 23, 2019 PoC Published
  • Jan 24, 2019 PoC Published
  • Jan 24, 2019 PoC Published
  • Jan 25, 2019 PoC Published
  • Jan 28, 2019 PoC Published
  • Jan 29, 2019 PoC Published
  • Mar 21, 2019 PoC Published
  • Mar 27, 2019 PoC Published
  • Mar 28, 2019 PoC Published
  • Mar 30, 2019 PoC Published

References

…and 4 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›