VYPR
Unrated severityNVD Advisory· Published Jun 20, 2019· Updated Nov 19, 2024

Cisco RV110W, RV130W, and RV215W Routers Information Disclosure Vulnerability

CVE-2019-1899

Description

A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing a specific URI on the web interface of the router.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated, remote attacker can obtain the list of devices connected to the guest network on Cisco RV110W, RV130W, and RV215W routers.

Vulnerability

The vulnerability exists in the web interface of Cisco RV110W, RV130W, and RV215W Wireless-N VPN Routers. Due to improper authorization of an HTTP request, an unauthenticated, remote attacker can access a specific URI to retrieve the list of devices that are or have been connected to the guest network. All firmware versions prior to the fix are affected [1][2].

Exploitation

An attacker needs only network access to the router's web interface; no authentication is required. By sending a crafted HTTP GET request to a particular URI (e.g., the endpoint that exposes guest network device information), the attacker can obtain the list of connected devices, including their MAC and IP addresses [1]. The exact URI is not publicly detailed but is reachable without any session or credentials.

Impact

Successful exploitation results in information disclosure: the attacker gains a list of all devices that have connected to the guest network, along with their MAC and IP addresses. This information can be leveraged for further attacks, such as targeted denial-of-service (see CVE-2019-1897) or network reconnaissance. The compromise is at the network information level, with no privilege escalation on the router itself [1][2].

Mitigation

Cisco has released firmware updates to address this vulnerability; affected users should upgrade to the fixed software version indicated in the Cisco Security Advisory [2]. No workarounds are available. Users should also consider disabling the guest network if not needed, and monitor for any suspicious activity. The routers may be end-of-life; check Cisco's support page for the latest guidance [2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.