#VU22600 Deserialization of Untrusted Data in Cisco Systems, Inc products - CVE-2019-15271
Published: November 8, 2019 / Updated: June 8, 2022
Cisco RV016 Multi-WAN VPN Router
Cisco RV042 Dual WAN VPN Router
Cisco RV042G Dual Gigabit WAN VPN Router
Cisco RV082 Dual WAN VPN Router
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data in the web-based management interface. A remote authenticated attacker can send a specially crafted HTTP request to the targeted device and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.