CVE-2019-15271
KEVlargeAuthenticated Deserialization RCE in Cisco RV016/RV042/RV042G/RV082 Routers
CISA: Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability
CVE-2019-15271 is a deserialization of untrusted data flaw (CWE-502) in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 VPN routers, caused by insufficient input validation of the HTTP payload. An authenticated, remote attacker—someone with valid credentials or an active session token—triggers it by sending a crafted HTTP request to the device's management web interface. Successful exploitation lets the attacker execute arbitrary commands with root privileges, giving full control of the router (traffic manipulation, pivoting into the network, and persistence). Any organization running these Small Business VPN routers is affected, especially where the management interface is reachable from the WAN or internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2022-06-08, though no public PoC is known and ransomware linkage is unknown; EPSS estimates a ~6% (93rd percentile) chance of exploitation within 30 days.
What to do: Apply updated firmware from Cisco per the vendor advisory — this is the required action in the CISA KEV entry — and, since these are older Small Business models with no guarantee of ongoing fixes, plan for hardware retirement. Until patched, do not expose the HTTP/HTTPS management interface to the internet (restrict it to trusted management hosts or VPN), use strong unique admin credentials, and review devices for unexpected sessions or configuration changes. Treat internet-exposed RV016/RV042/RV042G/RV082 units as potentially compromised given the KEV listing, and note recent reporting of network-equipment targeting by China-linked actors when prioritizing incident review.
| Cisco RV016 Multi-WAN VPN Router firmware | — |
| Cisco RV042 Dual WAN VPN Router firmware | — |
| Cisco RV042G Dual Gigabit WAN VPN Router firmware | — |
| Cisco RV082 Dual WAN VPN Router firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges.
- Affected
- Cisco RV Series Routers
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- rv016 multi-wan vpn firmware, rv042 dual wan vpn firmware, rv042g dual gigabit wan vpn firmware, rv082 dual wan vpn firmware
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H