ZeroHour

CVE-2019-15271

KEVlarge

Authenticated Deserialization RCE in Cisco RV016/RV042/RV042G/RV082 Routers

CISA: Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability

CVSS 3.1
8.8 high
EPSS
6%p93
Published
()
KEV added
AI analysis

CVE-2019-15271 is a deserialization of untrusted data flaw (CWE-502) in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 VPN routers, caused by insufficient input validation of the HTTP payload. An authenticated, remote attacker—someone with valid credentials or an active session token—triggers it by sending a crafted HTTP request to the device's management web interface. Successful exploitation lets the attacker execute arbitrary commands with root privileges, giving full control of the router (traffic manipulation, pivoting into the network, and persistence). Any organization running these Small Business VPN routers is affected, especially where the management interface is reachable from the WAN or internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2022-06-08, though no public PoC is known and ransomware linkage is unknown; EPSS estimates a ~6% (93rd percentile) chance of exploitation within 30 days.

What to do: Apply updated firmware from Cisco per the vendor advisory — this is the required action in the CISA KEV entry — and, since these are older Small Business models with no guarantee of ongoing fixes, plan for hardware retirement. Until patched, do not expose the HTTP/HTTPS management interface to the internet (restrict it to trusted management hosts or VPN), use strong unique admin credentials, and review devices for unexpected sessions or configuration changes. Treat internet-exposed RV016/RV042/RV042G/RV082 units as potentially compromised given the KEV listing, and note recent reporting of network-equipment targeting by China-linked actors when prioritizing incident review.

Affected
Cisco RV016 Multi-WAN VPN Router firmware
Cisco RV042 Dual WAN VPN Router firmware
Cisco RV042G Dual Gigabit WAN VPN Router firmware
Cisco RV082 Dual WAN VPN Router firmware
Estimated exposure
largetens of thousands of internet-exposed devices (estimate) — These are Cisco's long-selling legacy Small Business VPN router lines whose admin web UIs are commonly exposed to the WAN, and public internet-wide scans routinely surface Cisco RV-series management interfaces in the tens of thousands;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges.

CISA Known Exploited Vulnerability
Affected
Cisco RV Series Routers
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
rv016 multi-wan vpn firmware, rv042 dual wan vpn firmware, rv042g dual gigabit wan vpn firmware, rv082 dual wan vpn firmware
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news