CISA Known Exploited Vulnerability

CVE-2019-15271

Cisco · RV Series Routers

Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability

Date added
BOD 22-01 due date
CWE CWE-502
Ransomware Unknown

CISA description

A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges.

Required action

Apply updates per vendor instructions.