LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-1653: Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-1653 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed…

CVE-2019-1653 is an information disclosure vulnerability in Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers. Improper access controls on certain URLs can let an attacker obtain the router configuration or detailed diagnostic information. That material often includes credentials, VPN settings, and network topology details that can enable further compromise of the device or the networks behind it. IT and security teams should treat exposed management interfaces on these models as high priority until they confirm the vendor fix is applied.

How it works

The weakness is classified as CWE-284 (Improper Access Control). On the affected routers, certain URLs that serve configuration or diagnostic data do not enforce adequate access restrictions. An unauthenticated or insufficiently authorized remote attacker who can reach those URLs may retrieve the full configuration file or diagnostic output. Configuration dumps commonly contain plaintext or reversible credentials, pre-shared keys, firewall rules, and routing information. Once obtained, that data can be used to authenticate to the device, pivot into internal networks, or plan follow-on attacks. Exact request paths and any authentication bypass details must be confirmed against the vendor advisory; do not rely on third-party write-ups alone.

Am I affected? How to find it in your systems

These devices are Cisco Small Business RV320 and RV325 routers, typically deployed at branch offices, small businesses, or remote sites as dual-WAN VPN edge routers. They often sit at the perimeter with WAN interfaces reachable from the internet and LAN/VPN interfaces facing internal networks.

If you cannot determine the exact firmware level, assume the device is vulnerable until proven otherwise by the vendor’s fixed-release list.

How to remediate

Patch first. Apply the firmware updates published by Cisco for the RV320 and RV325 that address CVE-2019-1653, following the vendor’s installation instructions and any prerequisite steps. After upgrading, verify the new version string and reboot if required. CISA directs organizations to apply updates per vendor instructions.

If you can't patch immediately

Implement compensating controls while you schedule the firmware update:

These measures reduce risk but do not replace the vendor fix.

If your data may have been exposed

Actively exploited information-disclosure flaws on edge routers frequently lead to credential theft and broader network breaches. If logs or external scanning indicate that configuration or diagnostic data left the device, assume secrets are compromised: rotate passwords, VPN keys, and certificates, and review downstream systems for unauthorized access. You can run a free exposure scan of your email addresses to check whether they appear in known breach data sets and take additional account-protection steps as needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Small Business RV320 and RV325 Routers
WeaknessCWE-284
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities