CVE-2019-15258: Cisco SPA112 Firmware

Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper validation of user-supplied requests to the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the device to stop responding, requiring manual intervention for recovery.

Affected products

  • Cisco SPA112 Firmware: before 1.4.1 (fixed in 1.4.1); version 1.4.1 only
  • Cisco SPA122 Firmware: before 1.4.1 (fixed in 1.4.1); version 1.4.1 only

Published 2019-10-16. Last modified 2026-06-17.