HTTP: Cisco RV320 Dual Gigabit WAN VPN Router Command Injection

This signature detects attempts to exploit a known vulnerability against CISCO RV320. A successful attack can lead to remote code execution.

Extended Description

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root. Cisco has released firmware updates that address this vulnerability.

References

BugTraq: 106728

CVE: CVE-2019-1652

Short Name
HTTP:CISCO:RV320-DGWVR-CMD-INJ
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2019-1652 Cisco Command Dual Gigabit Injection RV320 Router VPN WAN bid:106728
Release Date
08/05/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3377
False Positive
Unknown
CVSS Score

9.0

Found a potential security threat?