{"cveID":"CVE-2019-1653","vendorProject":"Cisco","product":"Small Business RV320 and RV325 Routers","vulnerabilityName":"Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability","dateAdded":"2021-11-03","shortDescription":"Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-03","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2019-1653","cwes":["CWE-284"],"year":2019,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2019-1653","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"access_ctrl","comments":"CVE-2019-1653 is a critical information disclosure vulnerability affecting Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers. This vulnerability allows unauthenticated, remote attackers to access sensitive information from affected devices.","references":["https://thehackernews.com/2019/01/hacking-cisco-routers.html","https://therecord.media/cisco-routers-end-of-life-china-espionage-volt-typhoon"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2019-1653","technique":"T1005","technique_name_at_mapping":"Data from Local System","mapping_type":"secondary_impact","capability_group":"access_ctrl","comments":"CVE-2019-1653 is a critical information disclosure vulnerability affecting Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers. This vulnerability allows unauthenticated, remote attackers to access sensitive information from affected devices.","references":["https://thehackernews.com/2019/01/hacking-cisco-routers.html","https://therecord.media/cisco-routers-end-of-life-china-espionage-volt-typhoon"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2019-1653","technique":"T1007","technique_name_at_mapping":"System Service Discovery","mapping_type":"secondary_impact","capability_group":"access_ctrl","comments":"CVE-2019-1653 is a critical information disclosure vulnerability affecting Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers. This vulnerability allows unauthenticated, remote attackers to access sensitive information from affected devices.","references":["https://thehackernews.com/2019/01/hacking-cisco-routers.html","https://therecord.media/cisco-routers-end-of-life-china-espionage-volt-typhoon"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2019-1653","technique":"T1082","technique_name_at_mapping":"System Information Discovery","mapping_type":"primary_impact","capability_group":"access_ctrl","comments":"CVE-2019-1653 is a critical information disclosure vulnerability affecting Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers. This vulnerability allows unauthenticated, remote attackers to access sensitive information from affected devices.","references":["https://thehackernews.com/2019/01/hacking-cisco-routers.html","https://therecord.media/cisco-routers-end-of-life-china-espionage-volt-typhoon"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1005","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data from Local System","name_at_mapping":"Data from Local System","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":14,"has_detection_strategy":true},{"id":"T1007","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"System Service Discovery","name_at_mapping":"System Service Discovery","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":11,"has_detection_strategy":true},{"id":"T1082","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"System Information Discovery","name_at_mapping":"System Information Discovery","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":33,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}