CVE-2019-1652 — Cisco Small Business Routers Improper Input Validation Vulnerability
2022-03-03 • CISA Known Exploited Vulnerability
[event] A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | Cisco |
| Product | Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers |
| CWE | CWE-20 |
| CVE ID | CVE-2019-1652 |
| Date Added | 2022-03-03 |
| Due Date | 2022-03-17 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2022-03-17