S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 1, 2024

CVE-2019-1898 Scanner

Detects 'Information Disclosure' vulnerability in Cisco RV110W, RV130W, and RV215W Routers affects v. before 1.0.3.51.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-1898
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing the URL for the syslog file. A successful exploit could allow the attacker to access the information contained in the file.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Cisco RV130W Wireless-N Multifunction VPN Router Firmwareby Cisco
AFFECTED< 1.0.3.51SAFE ✓≥ 1.0.3.51
Updated Aug 21, 2026View on NVD →
Detail

Cisco RV110W, RV130W, and RV215W Routers are network routers that are designed for small businesses. These routers are used to provide internet connectivity, as well as secure access to resources within the local network. The routers are also equipped with a web-based management interface that allows network administrators to manage and configure the router settings. The interface provides access to various features of the router, such as network security settings, port forwarding, and VPN configuration.

The CVE-2019-1898 vulnerability was detected in the web-based management interface of these routers. This vulnerability allows an attacker to access the syslog file on an affected device without proper authorization. The syslog file contains valuable information about the network and its users, including login credentials and network activity logs. This vulnerability can be exploited using a simple HTTP request without the need for any authentication credentials.

A successful exploit of the CVE-2019-1898 vulnerability can lead to a data breach, as an attacker can gain access to sensitive information on the network. This can include login credentials, financial information, and other valuable data that can be used for malicious purposes. This vulnerability can also lead to a compromise of the network's security, as the attacker can use the information acquired to launch further attacks.

With the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform provides real-time monitoring and alerts of all potential security threats, giving users the ability to take immediate action and protect their assets. Users can also access detailed reports and recommended actions to help them better protect their digital assets and prevent data breaches.

 

REFERENCES

Solution Advice

 

There are several precautions that organizations can take to protect against this vulnerability, such as:

  • Applying the latest firmware updates released by Cisco for the affected products.
  • Restricting access to the web-based management interface of the routers to trusted IP addresses only.
  • Implementing strong password policies for accessing the management interface.
  • Monitoring network activity for any unusual behavior or unauthorized access.

 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.