Junglewise Threat Intelligence

CVE-2019-15271: Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability

CVE-2019-15271 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-06-08

Vendors: Cisco.

Executive brief

A deserialization of untrusted data vulnerability in the web-based management interface of Cisco Small Business RV Series Routers allows an authenticated, remote attacker to execute arbitrary commands with root privileges. The flaw exists due to insufficient input validation of HTTP payloads, requiring the attacker to possess valid credentials or an active session token.

Affected products

  • Cisco RV016 Multi-WAN VPN Router Firmware < 4.2.3.10
  • Cisco RV042 Dual WAN VPN Router Firmware < 4.2.3.10
  • Cisco RV042G Dual Gigabit WAN VPN Router Firmware < 4.2.3.10
  • Cisco RV082 Dual WAN VPN Router Firmware < 4.2.3.10

Timeline

  • 2019-11-06: advisory: Cisco published the original security advisory.
  • 2019-11-25: disclosed: NVD published the CVE entry.
  • 2022-06-08: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
  • 2022-06-08: exploited: Vulnerability reported as exploited in the wild.