CVE-2019-1652General(cisco / rv320)

LOWCVSS 7.2 · HIGHCISA KEV

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root. Cisco has released firmware updates that address this vulnerability.

2.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-03-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-20CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rv320
  • rv320_firmware
  • rv325
  • rv325_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
rv320rv320_firmwarerv325rv325_firmware

1 version affected across 4 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-08: 2PoC Mentioned / Linked · 2026-03-08: 1Technical Details · 2026-03-08: 103-08
Signal classification1 categories
General
2100.0%
Referenced assets4 URLs
Full discourse2 posts
  • KadinsGamingLounge@kadinsswitch
    General

    @MaddStep @Credib1eGuy @oliviscusAI I was actualy referring to how Carnegie Mellon’s DensePose project worked on exploiting Cisco routers. and how CVE-2019-1652 remote code execution at the time posed a threat for this vector of attack. Then again at DEFCON last year they were showing out to exploit them live

    Post summary

    The tweet cites CVE‑2019‑1652 as a remote code execution flaw in Cisco routers, notes that Carnegie Mellon’s DensePose project demonstrated an exploit, and describes a live demo at DEFCON, but it provides no evidence of active wild exploitation, patches, or false‑positive claims.

    10000223
    431 followersView on X
  • to0r@MaddStep
    General

    I was at Defcon 33 but maybe I missed this. I don't see cve-2019-1652 mentioned anywhere in https://www.ri.cmu.edu/app/uploads/2022/08/jiaqigen_msr_thesis.pdf either... When looking up https://nvd.nist.gov/vuln/detail/cve-2019-1652 I can see it effects https://www.amazon.com/Cisco-RV325-Dual-Gigabit-Router/dp/B00GSQJI4E and https://www.amazon.com/CISCO-DESIGNED-Rv320-Dual-Router/dp/B09M7SJSBL Neither of these appear to support WIFI out of the box... Sorry I just see how this is all tied together 😵‍💫 A Defcon video would be helpful.

    Post summary

    The user notes an absence of the CVE in a Defcon context and a PDF, and shows limited data on affected products, but provides no active exploitation, PoC, patch, or technical detail.

    00000197
    97 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWciscorv320---
OSciscorv320_firmware---
HWciscorv325---
OSciscorv325_firmware---

Explore more