CVE-2019-15271: Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-06-08. EPSS: 5.5% chance of exploitation in the next 30 days.
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges.
Affected products
- Cisco RV016 Multi-WAN VPN Firmware: before 4.2.3.10 (fixed in 4.2.3.10)
- Cisco RV042 Dual WAN VPN Firmware: before 4.2.3.10 (fixed in 4.2.3.10)
- Cisco RV042G Dual Gigabit WAN VPN Firmware: before 4.2.3.10 (fixed in 4.2.3.10)
- Cisco RV082 Dual WAN VPN Firmware: before 4.2.3.10 (fixed in 4.2.3.10)
Published 2019-11-26. Last modified 2026-06-17.