CVE-2019-15271

HIGH(8.8)KEV

Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability

Description

CVE-2019-15271 is a deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers. The flaw allows an authenticated attacker to execute arbitrary code with root privileges on the affected device by submitting crafted input to the management interface. Successful exploitation of this Cisco router vulnerability gives an attacker complete control over the network device, enabling traffic interception, network configuration changes, and lateral movement. CISA has added CVE-2019-15271 to its Known Exploited Vulnerabilities catalog, and with an EPSS score of 5.9% (90th percentile), this vulnerability warrants prompt remediation.

KEV Information

Vendor
Cisco
Product
RV Series Routers
Date Added
June 8, 2022
Due Date
June 22, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
ciscorv016 multi-wan vpn firmware< 4.2.3.10
ciscorv042 dual wan vpn firmware< 4.2.3.10
ciscorv042g dual gigabit wan vpn firmware< 4.2.3.10
ciscorv082 dual wan vpn firmware< 4.2.3.10

Multiple CVSS Assessments

Source: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: [email protected](Secondary)
8.8
HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-502: Deserialization of Untrusted Data

CVE-2019-15271 exploits a deserialization of untrusted data weakness in the Cisco RV Series Routers' management interface, where the device deserializes user-supplied data without sufficient verification. An attacker can craft malicious serialized payloads that, when deserialized by the router's management process, trigger arbitrary code execution with root privileges on the device.

Learn more: CWE-502 — Deserialization of Untrusted Data

Impact Analysis

CVE-2019-15271 allows an authenticated attacker to achieve root-level code execution on Cisco Small Business RV Series Routers through the web management interface. While authentication is required, the deserialization vulnerability allows privilege escalation from a standard authenticated user to root, the highest privilege level on the device. Confidentiality is critically impacted as root access enables interception and inspection of all network traffic passing through the router. Integrity is fully compromised as the attacker can modify routing tables, firewall rules, DNS settings, and VPN configurations. Availability is at risk as the attacker can disrupt network connectivity or render the device inoperable. The EPSS score of 5.9% (90th percentile) indicates meaningful exploitation probability, and given that routers are foundational network infrastructure, compromising one device can provide a pivotal position for attacking the entire network.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2019-15271 by including it in the Known Exploited Vulnerabilities catalog, with a remediation deadline of June 22, 2022. The EPSS score of 5.9% (90th percentile) reflects moderate but meaningful exploitation activity. No specific ransomware campaigns have been publicly associated with this vulnerability. However, deserialization vulnerabilities in network infrastructure devices are valuable to threat actors seeking persistent network access, and Cisco Small Business routers are widely deployed in organizations that may lack dedicated security monitoring for network device compromise.

Remediation

  1. Apply the Cisco firmware update immediately as directed by the CISA KEV catalog. Update all affected Cisco RV Series Routers to the latest firmware version that addresses CVE-2019-15271.
  2. Restrict access to the web management interface by configuring access control lists (ACLs) that limit management access to specific trusted IP addresses on a dedicated management VLAN.
  3. Disable remote management access if it is not strictly required for operations, ensuring the web-based management interface is only accessible from the local network.
  4. Implement strong authentication for router management accounts, using unique complex passwords and limiting the number of administrative accounts to the minimum necessary.
  5. Monitor router logs for anomalous management interface activity, including unexpected login attempts, configuration changes, or unusual traffic patterns that may indicate compromise through deserialization exploitation.

Technical Details

CVE-2019-15271 is a deserialization of untrusted data vulnerability in the web-based management interface of Cisco Small Business RV Series Routers. The management interface processes serialized data submitted through HTTP requests, but fails to properly validate the integrity and safety of the serialized input before deserializing it. An authenticated attacker can craft a malicious serialized payload that, when processed by the router's management service, instantiates objects or triggers operations that result in arbitrary code execution. Because the management service runs with root privileges on the router's embedded Linux operating system, the attacker's code executes at the highest privilege level, granting complete control over the device including the ability to modify firmware, intercept traffic, and establish persistent backdoor access.

Frequently Asked Questions

Is CVE-2019-15271 being actively exploited?

Yes. CISA has added CVE-2019-15271 to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The EPSS score of 5.9% (90th percentile) indicates meaningful exploitation activity. No ransomware campaigns have been specifically linked to this vulnerability.

What products are affected by CVE-2019-15271?

CVE-2019-15271 affects certain Cisco Small Business RV Series Routers. Specific affected models and firmware versions are detailed in the Cisco Security Advisory. These routers are commonly deployed in small and medium-sized business environments.

How do I fix CVE-2019-15271?

Apply the latest Cisco firmware update for the affected RV Series Router models. Restrict management interface access to trusted IP addresses, disable remote management if not needed, and implement strong authentication for administrative accounts.

How severe is CVE-2019-15271?

CVE-2019-15271 is a high-severity deserialization vulnerability with an EPSS score of 5.9% in the 90th percentile. While it requires authentication, successful exploitation grants root-level code execution on the router, enabling complete network compromise including traffic interception and configuration manipulation.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score5.98%
EPSS Percentile92.7%

Dates

PublishedNovember 26, 2019
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.