CVE-2015-6397: Cisco RV110W Wireless-N VPN Firewall Firmware

High severity, CVSS 8.8. EPSS: 2.3% chance of exploitation in the next 30 days.

Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCuv90139, CSCux58175, and CSCux73557.

Affected products

  • Cisco RV110W Wireless-N VPN Firewall Firmware: any version
  • Cisco RV130W Wireless-N Multifunction VPN Router Firmware: any version
  • Cisco RV215W Wireless-N VPN Router Firmware: any version

Published 2016-08-08. Last modified 2026-06-17.