← Vulnerability feed

Vulnerability record · CVE-2019-1653 · published 24 January 2019

CVE-2019-1653: Cisco RV320/RV325 router web interface improper access control

Cisco · Rv320 Firmware

The web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers has improper access controls for URLs, letting an unauthenticated remote attacker retrieve sensitive information. A successful request downloads the router configuration or detailed diagnostic data. Because these devices sit at the network edge and the flaw needs no credentials, exposed management interfaces are directly at risk.

7.5 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 100% · top 0.1% CWE-284 · Improper access control
7.5CVSS 3.1 base score, v2 5.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
31References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote retrieval of router configuration and diagnostic data on internet-facing edge devices, listed in CISA KEV with public exploits and near-maximum EPSS.

What it is

The web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers has improper access controls for URLs, letting an unauthenticated remote attacker retrieve sensitive information. A successful request downloads the router configuration or detailed diagnostic data. Because these devices sit at the network edge and the flaw needs no credentials, exposed management interfaces are directly at risk.

Impact

An attacker gains the router configuration and diagnostic data, which can include credentials, VPN keys and network details usable for further intrusion. The record does not state that this flaw alone yields code execution.

Attack surface

Reachable over the network via HTTP or HTTPS by requesting specific URLs on the affected device; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CISA added it to KEV on 2021-11-03 with a 2022-05-03 remediation due date, EPSS 30-day probability is 0.99876 (99.963rd percentile), and multiple references are tagged Exploit, including public configuration-export and diagnostic-retrieval exploits.

What to do

  • Apply the Cisco firmware updates referenced in the vendor advisory cisco-sa-20190123-rv-info as the first action.
  • If firmware cannot be applied immediately, block external access to the routers' HTTP/HTTPS management interface and restrict it to trusted management networks.
  • Replace or isolate end-of-support RV320/RV325 units that no longer receive firmware fixes.
  • Rotate any credentials, VPN keys or shared secrets that may have been exposed in a downloaded configuration.
  • Monitor for and investigate any prior unauthenticated requests to the management interface URLs.

Detection

  • Review web server or proxy logs for unauthenticated GET requests to configuration-export and diagnostic endpoints on RV320/RV325 management interfaces.
  • Alert on inbound HTTP/HTTPS connections to router management ports from untrusted or internet sources.
  • Hunt for known public exploit request patterns against these devices using the packetstorm, Exploit-DB and Full Disclosure references.
  • Check device logs and configuration change history for signs of configuration export or diagnostic data retrieval.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-1653 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/152260/Cisco-RV320-Unauthenticated-Configuration-Export.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/152261/Cisco-RV320-Unauthenticated-Diagnostic-Data-Retrieval.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/152305/Cisco-RV320-RV325-Unauthenticated-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2019/Mar/59 ExploitMailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2019/Mar/60 ExploitMailing ListThird Party Advisory
http://www.securityfocus.com/bid/106732 Third Party AdvisoryVDB Entry
https://badpackets.net/over-9000-cisco-rv320-rv325-routers-vulnerable-to-cve-2019-1653/ Third Party Advisory
https://seclists.org/bugtraq/2019/Mar/53 Mailing ListThird Party Advisory
https://seclists.org/bugtraq/2019/Mar/54 Mailing ListThird Party Advisory
https://threatpost.com/scans-cisco-routers-code-execution/141218/ Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-info Vendor Advisory
https://www.exploit-db.com/exploits/46262/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/46655/ Third Party AdvisoryVDB Entry
https://www.youtube.com/watch?v=bx0RQJDlGbY Third Party Advisory
https://www.zdnet.com/article/hackers-are-going-after-cisco-rv320rv325-routers-using-a-new-exploit/ Third Party Advisory
http://packetstormsecurity.com/files/152260/Cisco-RV320-Unauthenticated-Configuration-Export.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/152261/Cisco-RV320-Unauthenticated-Diagnostic-Data-Retrieval.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/152305/Cisco-RV320-RV325-Unauthenticated-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2019/Mar/59 ExploitMailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2019/Mar/60 ExploitMailing ListThird Party Advisory
http://www.securityfocus.com/bid/106732 Third Party AdvisoryVDB Entry
https://badpackets.net/over-9000-cisco-rv320-rv325-routers-vulnerable-to-cve-2019-1653/ Third Party Advisory
https://seclists.org/bugtraq/2019/Mar/53 Mailing ListThird Party Advisory
https://seclists.org/bugtraq/2019/Mar/54 Mailing ListThird Party Advisory
https://threatpost.com/scans-cisco-routers-code-execution/141218/ Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-info Vendor Advisory
https://www.exploit-db.com/exploits/46262/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/46655/ Third Party AdvisoryVDB Entry
https://www.youtube.com/watch?v=bx0RQJDlGbY Third Party Advisory
https://www.zdnet.com/article/hackers-are-going-after-cisco-rv320rv325-routers-using-a-new-exploit/ Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1653 US Government Resource

Track CVE-2019-1653 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2023-20118Cisco Small Business RV Series Routers Command InjectionThe web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 routers fails to properly validate user inpu…KEVEPSS 54%analysed7.2CVE-2019-1652Cisco RV320/RV325 web interface command injectionThe web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers fails to properly validate user-supplied inpu…KEVEPSS 96%analysed9.1CVE-2024-20520Cisco rv042 firmware stack-based buffer overflow vulnerabilityA vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, A…EPSS 0.61%9.1CVE-2024-20521Cisco rv042 firmware stack-based buffer overflow vulnerabilityA vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, A…EPSS 0.66%9.1CVE-2024-20518Cisco rv042 firmware stack-based buffer overflow vulnerabilityA vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, A…EPSS 0.61%9.1CVE-2024-20519Cisco rv042 firmware stack-based buffer overflow vulnerabilityA vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, A…EPSS 0.61%8.1CVE-2019-1828Cisco rv320 firmware broken cryptographic algorithm vulnerabilityA vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthentic…EPSS 0.70%7.2CVE-2023-20117Cisco rv320 firmware os command injection vulnerabilityMultiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an au…EPSS 30%

Source: NIST National Vulnerability Database (record CVE-2019-1653), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.