CVE-2019-15990: Cisco RV016 Multi-WAN VPN Firmware

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attacker to view information displayed in the web-based management interface. The vulnerability is due to improper authorization of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to view information displayed in the web-based management interface without authentication.

Affected products

  • Cisco RV016 Multi-WAN VPN Firmware: before 4.2.3.10 (fixed in 4.2.3.10)
  • Cisco RV042 Dual WAN VPN Firmware: before 4.2.3.10 (fixed in 4.2.3.10)
  • Cisco RV042G Dual Gigabit WAN VPN Firmware: before 4.2.3.10 (fixed in 4.2.3.10)
  • Cisco RV082 Dual WAN VPN Firmware: before 4.2.3.10 (fixed in 4.2.3.10)

Published 2019-11-26. Last modified 2026-06-17.