CVE-2019-1899
Cisco RV110W, RV130W, and RV215W Routers Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing a specific URI on the web interface of the router.
Una vulnerabilidad en la interfaz web de los enrutadores RV110W, RV130W y RV215W de Cisco, podría permitir que un atacante remoto no autenticado adquiera la lista de dispositivos que están conectados en la red de invitado. Una vulnerabilidad es debido a la autorización inapropiada de una petición HTTP. Un atacante podría explotar esta vulnerabilidad al acceder a un URI específico en la interfaz web del enrutador.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-06 CVE Reserved
- 2019-06-20 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- 2024-11-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-285: Improper Authorization
- CWE-425: Direct Request ('Forced Browsing')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/108867 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.tenable.com/security/research/tra-2019-29 | 2024-09-16 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Rv110w Firmware Search vendor "Cisco" for product "Rv110w Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv110w Search vendor "Cisco" for product "Rv110w" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Rv130w Firmware Search vendor "Cisco" for product "Rv130w Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv130w Search vendor "Cisco" for product "Rv130w" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Rv215w Firmware Search vendor "Cisco" for product "Rv215w Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv215w Search vendor "Cisco" for product "Rv215w" | - | - |
Safe
|