← Vulnerability feed

Vulnerability record · CVE-2019-15271 · published 26 November 2019

CVE-2019-15271: Cisco RV Series Routers web interface command injection via untrusted deserialization

Cisco · Rv016 Multi Wan Vpn Firmware

The web-based management interface of several Cisco Small Business RV Series Routers fails to validate HTTP payload input, allowing deserialization of untrusted data that leads to arbitrary command execution. An attacker who already holds valid credentials or an active session token can run commands as root on the device. Because the routers sit at the network edge, full compromise exposes the traffic and configuration they manage.

8.8 CVSS 3.1 High CISA KEV since 8 Jun 2022 EPSS 5.5% · top 7.5% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score, v2 9.0
5.5%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw yields root command execution on edge routers and is confirmed exploited in CISA KEV, though it requires valid credentials or a session token.

What it is

The web-based management interface of several Cisco Small Business RV Series Routers fails to validate HTTP payload input, allowing deserialization of untrusted data that leads to arbitrary command execution. An attacker who already holds valid credentials or an active session token can run commands as root on the device. Because the routers sit at the network edge, full compromise exposes the traffic and configuration they manage.

Impact

An authenticated attacker gains root-level command execution on the router, allowing full control of the device, its configuration and any traffic passing through it.

Attack surface

Reachable remotely over the network through the router's web-based management interface via a crafted HTTP request; the attacker must supply a valid credential or an active session token, and no user interaction is required.

Exploitation

CVE-2019-15271 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-08), indicating exploitation in the wild; EPSS gives a 30-day probability of about 6.0 percent (92.9th percentile). No ransomware campaign use is documented.

What to do

  • Apply the vendor updates referenced in Cisco advisory cisco-sa-20191106-sbrv-cmd-x for the affected RV016, RV042, RV042G and RV082 firmware.
  • If the device is end-of-support or no patch is available, replace it or disable and block remote access to the web management interface.
  • Restrict management interface access to a trusted internal network or VPN and never expose it to the internet.
  • Rotate administrative credentials and invalidate active session tokens, since a valid credential or session is required to exploit.
  • Monitor vendor guidance for end-of-life status and plan hardware replacement where fixes are unavailable.

Detection

  • Review web management interface logs for malformed or anomalous HTTP requests, especially POST bodies containing serialized object data.
  • Alert on unexpected outbound connections or new processes on the router that indicate command execution.
  • Audit authentication logs for logins from unusual source addresses or at unusual times that could precede exploitation.
  • Check for configuration changes or new administrative accounts created outside normal change windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-15271 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-15271 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2019-15957Cisco rv016 multi-wan vpn firmware improper input validation vulnerabilityA vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker…EPSS 3.2%5.3CVE-2019-15990Cisco rv016 multi-wan vpn firmware improper authorization vulnerabilityA vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attack…EPSS 1.2%4.3CVE-2015-6418Cisco sa520 information exposure vulnerabilityThe random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have sufficient entropy, which makes…EPSS 1.8%9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 90%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed8.8CVE-2026-45659Microsoft SharePoint Server deserialization flaw enables remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an authenticated attacker run code over the network. The flaw is remotely reachable,…KEVEPSS 2.7%analysed

Source: NIST National Vulnerability Database (record CVE-2019-15271), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.