imPC@ndo IT

Tracker / CVE-2019-15271

CVE-2019-15271

Exploited High 8.8

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges.

Affected products and versions

cisco rv016_multi-wan_vpn_firmware · … → 4.2.3.10
cisco rv042_dual_wan_vpn_firmware · … → 4.2.3.10
cisco rv042g_dual_gigabit_wan_vpn_firmware · … → 4.2.3.10
cisco rv082_dual_wan_vpn_firmware · … → 4.2.3.10

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References