CVE-2019-1724 describes a session management vulnerability in the web-based interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers. An unauthenticated, remote attacker could exploit this flaw by sending a crafted HTTP request to hijack an active, authorized user session. This could allow the attacker to gain control of the device with the privileges of the impersonated session, potentially creating new user accounts or altering device configurations. The vulnerability has a high CVSS score of 8.8, indicating a critical severity due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Exploitation requires an active user session and the ability to craft specific HTTP requests. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.1.12CPE matchmatch criteria | cpe:2.3:o:cisco:rv325_dual_wan_gigabit_vpn_router_firmware:1.3.1.12:*:*:*:*:*:*:* | ||
1.3.1.12CPE matchmatch criteria | cpe:2.3:o:cisco:rv320_dual_gigabit_wan_vpn_router_software:1.3.1.12:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.