CRITICAL

CVE-2019-1663

CVSS v3

9.8

CRITICAL

EPSS Score

86.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit this vulnerability by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user. RV110W Wireless-N VPN Firewall versions prior to 1.2.2.1 are affected. RV130W Wireless-N Multifunction VPN Router versions prior to 1.0.3.45 are affected. RV215W Wireless-N VPN Router versions prior to 1.3.1.1 are affected.

Technical details

Published
2/28/2019

Frequently asked questions

What is CVE-2019-1663?

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit this vulnerability by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user. RV110W Wireless-N VPN Firewall versions prior to 1.2.2.1 are affected. RV130W Wireless-N Multifunction VPN Router versions prior to 1.0.3.45 are affected. RV215W Wireless-N VPN Router versions prior to 1.3.1.1 are affected.

Is CVE-2019-1663 actively exploited?

Active exploitation of CVE-2019-1663 has not been confirmed. The EPSS score is 86.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-1663?

CVE-2019-1663 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-1663 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.