ZeroHour

CVE-2019-1652

KEV PoC ×5moderate

Authenticated Command Injection in Cisco RV320/RV3325 Small Business Routers

CISA: Cisco Small Business Routers Improper Input Validation Vulnerability

CVSS 3.1
7.2 high
EPSS
96%p100
Published
()
KEV added
AI analysis

CVE-2019-1652 is an improper input validation flaw (CWE-20, leading to command injection per CWE-78) in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN routers. An authenticated, remote attacker who already holds administrative privileges on the device exploits it by sending crafted HTTP POST requests to the management interface, and a successful exploit allows arbitrary command execution as root on the underlying Linux shell. Because administrative credentials are required, the bug is typically a second stage of an attack on an internet-facing edge router rather than a standalone entry point. All RV320 and RV325 routers running firmware predating the firmware updates Cisco released are affected, and these models have since reached end-of-life. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV catalog on 2022-03-03, carries a 95.9% EPSS probability (100th percentile), has had public PoCs since 2019, and news coverage reports attackers — including China-linked groups — targeting the roughly 9,000 RV320/RV325 units exposed online.

What to do: Apply the firmware updates Cisco released for the RV320/RV325 per the vendor advisory, as required by the CISA KEV listing, and since these routers are end-of-life, plan hardware replacement where the updated firmware cannot be installed. In the interim, restrict access to the web-based management interface to trusted networks only and check exposed devices for signs of compromise, given active targeting by China-linked threat actors.

Affected
Cisco Small Business RV320 Dual Gigabit WAN VPN Router (firmware)
Cisco Small Business RV325 Dual Gigabit WAN VPN Router (firmware)
Estimated exposure
moderate≈9,000+ internet-exposed RV320/RV325 routers per public scans; total deployed base unknown but larger — News coverage of the flaw cites public internet scans counting over 9,000 RV320/RV325 devices exposed online; since these small-business edge routers are widely deployed and many are unexposed or uncounted, the full installed base is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root. Cisco has released firmware updates that address this vulnerability.

CISA Known Exploited Vulnerability
Affected
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
rv320 firmware, rv325 firmware
Weakness
CWE-20, CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news