LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-1652: Cisco Small Business Routers Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-1652 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges…

CVE-2019-1652 is an improper input validation flaw in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers. An authenticated remote attacker who already holds administrative privileges on an affected device can use it to execute arbitrary commands. For IT and security teams, this matters because these routers often sit at the network edge; successful abuse can give an attacker deep control of the device and a foothold into the rest of the environment.

Public detail is limited to the CISA description and the CWE classification. Confirm exact affected firmware, fixed releases, and any additional constraints directly against the vendor advisory before acting.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). In this class of flaw, the web management interface fails to adequately check or sanitize data supplied by an authenticated administrator. An attacker who already possesses admin credentials can submit crafted input through that interface; because the input is not properly validated, the device processes it in a way that results in arbitrary command execution on the underlying system.

No public exploit mechanics beyond the CISA summary are provided here. The attack requires existing administrative privileges, so it is not a pre-authentication remote code execution path. Once command execution is achieved, the attacker can typically alter configuration, install persistence, or pivot further, depending on how the router is deployed. Always verify the precise attack surface and any prerequisites in the official Cisco advisory.

Am I affected? How to find it in your systems

These devices are Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers, commonly used by small and mid-size organizations as edge VPN and dual-WAN gateways. They are typically managed through a web interface reachable from the LAN or, if exposed, from the internet.

How to remediate

Patch first. Apply the updates Cisco published for this vulnerability, following the exact instructions in the vendor advisory. CISA’s required action is simply to apply updates per vendor instructions.

If you can't patch immediately

If immediate firmware upgrade is not possible, reduce exposure with compensating controls while you prepare the patch.

These steps do not eliminate the vulnerability; they only lower the likelihood of successful abuse until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities on edge devices can lead to broader compromise and data exposure. Known ransomware use of this specific CVE is not documented in the supplied facts. If you suspect the device was abused, isolate it, preserve logs, and begin incident-response procedures. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated credentials or personal information have appeared in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers
WeaknessCWE-20
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities