peter bassill · operator
$ cve CVE-2019-15271 JSON

CVE-2019-15271 KEV

8.8
HIGH · CVSS 3.1 · EPSS 5.5% (pctl 92)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-22.

Description

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS5.49% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2022-06-22
Public exploitnone known
Published2019-11-26
Last modified2026-06-17

CISA KEV

NameCisco RV Series Routers Deserialization of Untrusted Data Vulnerability
Added2022-06-08
Due2022-06-22
Vendor / productCisco / RV Series Routers
Ransomware usenone reported

Affected (8)

VendorProduct
ciscorv016 multi-wan vpn
ciscorv016 multi-wan vpn firmware
ciscorv042 dual wan vpn
ciscorv042 dual wan vpn firmware
ciscorv042g dual gigabit wan vpn
ciscorv042g dual gigabit wan vpn firmware
ciscorv082 dual wan vpn
ciscorv082 dual wan vpn firmware

References

→ the Explorer  ·  watch your stack  ·  NVD