S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-1653 Scanner

CVE-2019-1653 scanner - Information Disclosure vulnerability in Cisco Small Business RV Series Router

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-1653
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Cisco Small Business RV Series Router Firmwareby Cisco
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Cisco Small Business RV Series Router is a popular networking device used mainly by small businesses to provide secure and reliable access to the internet. These dual Gigabit WAN VPN routers provide high-performance connectivity and advanced security features for small businesses and home offices. They offer multiple WAN connections with load balancing and failover, VPN support, and a web-based management interface for easy configuration and management.

However, a serious vulnerability, identified as CVE-2019-1653, has been detected in these routers, which could allow an unauthenticated attacker to retrieve sensitive information from the web-based management interface. This vulnerability is due to improper access controls for URLs and can be exploited by connecting to an affected device via HTTP or HTTPS and requesting specific URLs.

If this vulnerability is exploited, an attacker can easily retrieve the router configuration or detailed diagnostic information. This sensitive information can be used to further compromise the network, steal valuable data, or launch other malicious attacks.

In conclusion, as a trusted source of security information and solutions, s4e.io provides comprehensive coverage of vulnerabilities affecting various digital assets, including network devices, web applications, and operating systems. By subscribing to our platform, users can easily and quickly learn about vulnerabilities affecting their digital assets and take proactive measures to protect their networks and data. We are committed to delivering timely and accurate information to help our customers stay secure in today's ever-evolving threat landscape.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of the affected routers must install the latest firmware updates released by Cisco. Additionally, they should take the following precautions:

  • Disable remote management if not needed
  • Use strong passwords and change them regularly
  • Limit access to the web-based management interface to trusted users only
  • Monitor network traffic for any unusual activity
  • Use a reputable security solution to scan for vulnerabilities on a regular basis

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-1653 scanner - Information Disclosure vulnerability in Cisco Small Business RV Series Router S4E