← Vulnerability feed

Vulnerability record · CVE-2019-15276 · published 26 November 2019

CVE-2019-15276: Cisco Wireless LAN Controller web interface URL parsing DoS

Cisco · Wireless Lan Controller Software

Cisco Wireless LAN Controller Software fails to properly validate specially crafted URLs in its web interface HTTP parsing engine. A low-privileged authenticated remote attacker, or an unauthenticated attacker who convinces a logged-in user to click a crafted URL, can trigger an unexpected device restart. The result is a denial of service on the controller, which can disrupt managed wireless access.

6.5 CVSS 3.1 Medium EPSS 46% · top 1.2% CWE-20 · Improper input validation
6.5CVSS 3.1 base score, v2 4.0
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to handle specially crafted URLs. An attacker could exploit this vulnerability by authenticating with low privileges to an affected controller and submitting the crafted URL to the web interface of the affected device. Conversely, an unauthenticated attacker could exploit this vulnerability by persuading a user of the web interface to click the crafted URL. A successful exploit could allow the attacker to cause an unexpected restart of the device, resulting in a DoS condition.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityThe flaw causes full availability loss on a network-critical controller, a public exploit reference exists, and EPSS is high despite the medium CVSS score and no KEV listing.

What it is

Cisco Wireless LAN Controller Software fails to properly validate specially crafted URLs in its web interface HTTP parsing engine. A low-privileged authenticated remote attacker, or an unauthenticated attacker who convinces a logged-in user to click a crafted URL, can trigger an unexpected device restart. The result is a denial of service on the controller, which can disrupt managed wireless access.

Impact

An attacker can force an unexpected restart of the affected controller, causing a denial of service and loss of wireless management or connectivity for dependent access points and clients. No confidentiality or integrity impact is described; the effect is availability only.

Attack surface

Reachable over the network through the controller web interface. Exploitation requires either low-privileged authentication or, for an unauthenticated attacker, user interaction in the form of a victim clicking a crafted URL.

Exploitation

Not listed in CISA KEV, but a public exploit reference exists (Packet Storm advisory tagged Exploit) and EPSS is high at roughly 0.46 probability (98.8th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the Cisco security advisory cisco-sa-20191106-wlc-dos fix for affected Wireless LAN Controller Software versions.
  • Restrict web interface access to trusted management networks and disable it where not required.
  • Enforce least privilege so few accounts hold even low-privileged web access.
  • Filter or block malformed and suspicious URL patterns at the management boundary.
  • Monitor controller restarts and correlate them with web interface access logs.

Detection

  • Alert on unexpected controller restarts or reboots and correlate with web interface sessions.
  • Review web interface access logs for malformed or unusually crafted URL requests.
  • Monitor for low-privileged accounts submitting anomalous HTTP requests to the controller.
  • Track authentication events followed closely by device restart or availability loss.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-15276 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-0703Cisco wireless lan controller software race condition vulnerabilityCisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the administr…EPSS 2.0%10.0CVE-2007-2036Cisco wireless lan controller software vulnerabilityThe SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-…EPSS 2.6%9.8CVE-2016-1363Cisco wireless lan controller software vulnerabilityBuffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through…EPSS 5.6%9.8CVE-2015-6314Cisco wireless lan controller software improper authentication vulnerabilityCisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change conf…EPSS 3.0%9.3CVE-2012-0371Cisco wireless lan controller software permissions and access controls vulnerabilityCisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.4, when CPU-based ACLs are enabled, allow remote atta…EPSS 1.8%9.0CVE-2013-1105Cisco wireless lan controller software permissions and access controls vulnerabilityCisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.3, 7.1 and 7.2 before 7.2.111.3, and 7.3 before 7.3.101.0 allow remote a…EPSS 3.1%9.0CVE-2013-1104Cisco 2000 wireless lan controller vulnerabilityThe HTTP Profiling functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.3.101.0 allows remote authenticated users to execute …EPSS 3.7%9.0CVE-2010-2843Cisco wireless lan controller software permissions and access controls vulnerabilityCisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and …EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2019-15276), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.