Vulnerability record · CVE-2019-15271 · published 26 November 2019
CVE-2019-15271: Cisco RV Series Routers web interface command injection via untrusted deserialization
Cisco · Rv016 Multi Wan Vpn Firmware
The web-based management interface of several Cisco Small Business RV Series Routers fails to validate HTTP payload input, allowing deserialization of untrusted data that leads to arbitrary command execution. An attacker who already holds valid credentials or an active session token can run commands as root on the device. Because the routers sit at the network edge, full compromise exposes the traffic and configuration they manage.
Description
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw yields root command execution on edge routers and is confirmed exploited in CISA KEV, though it requires valid credentials or a session token.
What it is
The web-based management interface of several Cisco Small Business RV Series Routers fails to validate HTTP payload input, allowing deserialization of untrusted data that leads to arbitrary command execution. An attacker who already holds valid credentials or an active session token can run commands as root on the device. Because the routers sit at the network edge, full compromise exposes the traffic and configuration they manage.
Impact
An authenticated attacker gains root-level command execution on the router, allowing full control of the device, its configuration and any traffic passing through it.
Attack surface
Reachable remotely over the network through the router's web-based management interface via a crafted HTTP request; the attacker must supply a valid credential or an active session token, and no user interaction is required.
Exploitation
CVE-2019-15271 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-08), indicating exploitation in the wild; EPSS gives a 30-day probability of about 6.0 percent (92.9th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor updates referenced in Cisco advisory cisco-sa-20191106-sbrv-cmd-x for the affected RV016, RV042, RV042G and RV082 firmware.
- If the device is end-of-support or no patch is available, replace it or disable and block remote access to the web management interface.
- Restrict management interface access to a trusted internal network or VPN and never expose it to the internet.
- Rotate administrative credentials and invalidate active session tokens, since a valid credential or session is required to exploit.
- Monitor vendor guidance for end-of-life status and plan hardware replacement where fixes are unavailable.
Detection
- Review web management interface logs for malformed or anomalous HTTP requests, especially POST bodies containing serialized object data.
- Alert on unexpected outbound connections or new processes on the router that indicate command execution.
- Audit authentication logs for logins from unusual source addresses or at unusual times that could precede exploitation.
- Check for configuration changes or new administrative accounts created outside normal change windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-15271 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-15271 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-15271), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.