ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Cisco botched patches for its RV320/RV325 routers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-1652
Authenticated Command Injection in Cisco RV320/RV3325 Small Business Routers

CVE-2019-1652 is an improper input validation flaw (CWE-20, leading to command injection per CWE-78) in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN routers. An authenticated, remote attacker who already holds administrative privileges on the device exploits it by sending crafted HTTP POST requests to the management interface, and a successful exploit allows arbitrary command execution as root on the underlying Linux shell. Because administrative credentials are required, the bug is typically a second stage of an attack on an internet-facing edge router rather than a standalone entry point. All RV320 and RV325 routers running firmware predating the firmware updates Cisco released are affected, and these models have since reached end-of-life. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV catalog on 2022-03-03, carries a 95.9% EPSS probability (100th percentile), has had public PoCs since 2019, and news coverage reports attackers — including China-linked groups — targeting the roughly 9,000 RV320/RV325 units exposed online.

Do: Apply the firmware updates Cisco released for the RV320/RV325 per the vendor advisory, as required by the CISA KEV listing, and since these routers are end-of-life, plan hardware replacement where the updated firmware cannot be installed. In the interim, restrict access to the web-based management interface to trusted networks only and check exposed devices for signs of compromise, given active targeting by China-linked threat actors.

7.296% KEV PoC ×5
  • Cisco Small Business RV320 Dual Gigabit WAN VPN Router (firmware)
  • Cisco Small Business RV325 Dual Gigabit WAN VPN Router (firmware)
moderate≈9,000+ internet-exposed RV320/RV325 routers per public scans; total deployed base unknown but larger
CVE-2019-1653
Unauthenticated Config Disclosure in Cisco RV320/RV325 Routers

CVE-2019-1653 is an improper access control flaw (CWE-284) in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN routers. It is triggered by sending requests to vulnerable URLs on the management interface without authentication, bypassing the intended access controls. An attacker gains the ability to download the full router configuration — which can expose credentials and VPN/VPN-tunnel settings — as well as detailed diagnostic information about the device. Any Cisco RV320 or RV325 router whose management interface is reachable, particularly over the internet, is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and carries a 99.9% EPSS score, though no public proof-of-concept is known and no ransomware association has been confirmed.

Do: Apply the updated router firmware from Cisco as instructed in the vendor advisory, per the CISA KEV required action. If updating is not immediately possible, restrict or disable WAN-side access to the web management interface and limit it to trusted management hosts. Because the downloaded configuration can contain credentials, change administrative and VPN passwords after patching, and review logs for signs of unauthenticated configuration downloads.

7.5100% KEV PoC ×5
  • Cisco Small Business RV320 Dual Gigabit WAN VPN Router
  • Cisco Small Business RV325 Dual Gigabit WAN VPN Router
largetens of thousands of internet-exposed routers (public internet-wide scans at disclosure found on the order of 20,000–30,000 RV320/RV325 devices with reachable…
Full article303 words · extracted from helpnetsecurity.com · click to collapse

Cisco RV320 and RV325 WAN VPN routers are still vulnerable to attack through two flaws that Cisco had supposedly patched.

#Cisco Small Business Routers still vulnerable to remote code execution & configuration export due to incomplete patch 🚨 #RCE #RV320 #RV325 New advisories: https://t.co/fPzrrkb3Hk https://t.co/xZex3wdfpb https://t.co/iZUuCCEnGx

— RedTeam Pentesting (@RedTeamPT) March 27, 2019

There are still many vulnerable devices

CVE-2019-1652 and CVE-2019-1653 were discovered in September 2018 by security experts from RedTeam Pentesting and disclosed to Cisco, which delivered patches in January 2019.

Unfortunately, the patches did not fix the vulnerabilities, but merely blacklisted the user agent for curl, a command-line tool for transferring data that is used by many popular Internet scanning tools.

That discovery was again made by RedTeam Pentesting, and the vulnerabilities continue to allow attackers with administrative access to the router’s web interface to:

  • Execute arbitrary operating system commands on the device (CVE-2019-1652), and/or
  • Gather configuration and diagnostic information that can be used to compromise the device or attached networks (CVE-2019-1653). “By downloading the configuration/diagnostic information, attackers can obtain internal network configuration, VPN or IPsec secrets, as well as password hashes for the router’s user accounts,” they pointed out.

Complete fixes are on the way

Cisco has confirmed their findings and has promised to release new, complete fixes by the middle of April 2019.

Troy Mursch of Bad Packets Report says attackers have been trying to exploit the flaws (especially CVE-2019-1653) since January, and there are currently over 8,000 vulnerable routers Cisco RV320/RV325 routers out there that attackers can extract configuration settings from.

Cisco says there are no workarounds that address these vulnerabilities, but RedTeam Pentesting experts note that the threat of attack can be mitigated by preventing untrusted users from using the vulnerable routers’ web interface and by preventing untrusted clients from connecting to the devices’ web server.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/03/28/cisco-botched-patches-for-its-rv320-rv325-routers/