Executive brief
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 routers due to improper access controls for URLs allows unauthenticated remote attackers to retrieve sensitive information. By requesting specific URLs via HTTP or HTTPS, an attacker can download the router configuration or detailed diagnostic information.
Affected products
- Cisco RV320 Dual Gigabit WAN VPN Router
- Cisco RV325 Dual Gigabit WAN VPN Router
Timeline
- 2019-01-23: advisory: Initial Cisco security advisory published
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- exploited: Reported as exploited in the wild by multiple sources including CISA and ZDNet.
- patched: Cisco released firmware updates to address the vulnerability.