CVE-2019-1652
KEV PoC ×5moderateAuthenticated Command Injection in Cisco RV320/RV3325 Small Business Routers
CISA: Cisco Small Business Routers Improper Input Validation Vulnerability
CVE-2019-1652 is an improper input validation flaw (CWE-20, leading to command injection per CWE-78) in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN routers. An authenticated, remote attacker who already holds administrative privileges on the device exploits it by sending crafted HTTP POST requests to the management interface, and a successful exploit allows arbitrary command execution as root on the underlying Linux shell. Because administrative credentials are required, the bug is typically a second stage of an attack on an internet-facing edge router rather than a standalone entry point. All RV320 and RV325 routers running firmware predating the firmware updates Cisco released are affected, and these models have since reached end-of-life. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV catalog on 2022-03-03, carries a 95.9% EPSS probability (100th percentile), has had public PoCs since 2019, and news coverage reports attackers — including China-linked groups — targeting the roughly 9,000 RV320/RV325 units exposed online.
What to do: Apply the firmware updates Cisco released for the RV320/RV325 per the vendor advisory, as required by the CISA KEV listing, and since these routers are end-of-life, plan hardware replacement where the updated firmware cannot be installed. In the interim, restrict access to the web-based management interface to trusted networks only and check exposed devices for signs of compromise, given active targeting by China-linked threat actors.
| Cisco Small Business RV320 Dual Gigabit WAN VPN Router (firmware) | — |
| Cisco Small Business RV325 Dual Gigabit WAN VPN Router (firmware) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root. Cisco has released firmware updates that address this vulnerability.
- Affected
- Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- rv320 firmware, rv325 firmware
- Weakness
- CWE-20, CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H