Vulnerability record · CVE-2019-1653 · published 24 January 2019
CVE-2019-1653: Cisco RV320/RV325 router web interface improper access control
Cisco · Rv320 Firmware
The web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers has improper access controls for URLs, letting an unauthenticated remote attacker retrieve sensitive information. A successful request downloads the router configuration or detailed diagnostic data. Because these devices sit at the network edge and the flaw needs no credentials, exposed management interfaces are directly at risk.
Description
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityUnauthenticated remote retrieval of router configuration and diagnostic data on internet-facing edge devices, listed in CISA KEV with public exploits and near-maximum EPSS.
What it is
The web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers has improper access controls for URLs, letting an unauthenticated remote attacker retrieve sensitive information. A successful request downloads the router configuration or detailed diagnostic data. Because these devices sit at the network edge and the flaw needs no credentials, exposed management interfaces are directly at risk.
Impact
An attacker gains the router configuration and diagnostic data, which can include credentials, VPN keys and network details usable for further intrusion. The record does not state that this flaw alone yields code execution.
Attack surface
Reachable over the network via HTTP or HTTPS by requesting specific URLs on the affected device; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CISA added it to KEV on 2021-11-03 with a 2022-05-03 remediation due date, EPSS 30-day probability is 0.99876 (99.963rd percentile), and multiple references are tagged Exploit, including public configuration-export and diagnostic-retrieval exploits.
What to do
- Apply the Cisco firmware updates referenced in the vendor advisory cisco-sa-20190123-rv-info as the first action.
- If firmware cannot be applied immediately, block external access to the routers' HTTP/HTTPS management interface and restrict it to trusted management networks.
- Replace or isolate end-of-support RV320/RV325 units that no longer receive firmware fixes.
- Rotate any credentials, VPN keys or shared secrets that may have been exposed in a downloaded configuration.
- Monitor for and investigate any prior unauthenticated requests to the management interface URLs.
Detection
- Review web server or proxy logs for unauthenticated GET requests to configuration-export and diagnostic endpoints on RV320/RV325 management interfaces.
- Alert on inbound HTTP/HTTPS connections to router management ports from untrusted or internet sources.
- Hunt for known public exploit request patterns against these devices using the packetstorm, Exploit-DB and Full Disclosure references.
- Check device logs and configuration change history for signs of configuration export or diagnostic data retrieval.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-1653 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-1653 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1653), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.