Vulnerability record · CVE-2019-1663 · published 28 February 2019
CVE-2019-1663: Cisco RV110W/RV130W/RV215W web management interface buffer overflow RCE
Cisco · Rv110w Firmware
The web-based management interface of the Cisco RV110W, RV130W and RV215W routers fails to properly validate user-supplied data, allowing an out-of-bounds write (CWE-787) and memory buffer overflow (CWE-119). An unauthenticated remote attacker can send crafted HTTP requests to execute arbitrary code as a high-privilege user on the device. Because these are edge VPN routers/firewalls, compromise gives a foothold at the network perimeter.
Description
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit this vulnerability by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user. RV110W Wireless-N VPN Firewall versions prior to 1.2.2.1 are affected. RV130W Wireless-N Multifunction VPN Router versions prior to 1.0.3.45 are affected. RV215W Wireless-N VPN Router versions prior to 1.3.1.1 are affected.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code available, and a very high EPSS score make this an urgent perimeter risk.
What it is
The web-based management interface of the Cisco RV110W, RV130W and RV215W routers fails to properly validate user-supplied data, allowing an out-of-bounds write (CWE-787) and memory buffer overflow (CWE-119). An unauthenticated remote attacker can send crafted HTTP requests to execute arbitrary code as a high-privilege user on the device. Because these are edge VPN routers/firewalls, compromise gives a foothold at the network perimeter.
Impact
An attacker gains arbitrary code execution on the underlying operating system with high privileges, giving full control of the device and a position to pivot into the internal network.
Attack surface
Reached over the network through the web-based management interface via malicious HTTP requests; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and description confirm no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.957, 99.9th percentile) and multiple references are tagged Exploit, including a Rapid7 Metasploit module and an Exploit-DB entry, indicating public exploit code exists.
What to do
- Upgrade to fixed firmware: RV110W 1.2.2.1 or later, RV130W 1.0.3.45 or later, RV215W 1.3.1.1 or later.
- If patching is not possible, disable remote management and restrict the web interface to trusted internal management networks only.
- Block or filter external access to the routers' HTTP/HTTPS management ports at the network edge.
- Replace end-of-life devices that no longer receive firmware updates.
- Monitor vendor advisory cisco-sa-20190227-rmi-cmd-ex for updated guidance.
Detection
- Inspect HTTP requests to the management interface for oversized or malformed parameters that could trigger the buffer overflow.
- Alert on unexpected processes, outbound connections, or configuration changes originating from the router.
- Review router logs for authentication bypass or anomalous management-interface access from untrusted sources.
- Scan the network for RV110W/RV130W/RV215W devices running firmware below the fixed versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-1663 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1663), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.