CVE-2019-1663 Details
Description
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit this vulnerability by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user. RV110W Wireless-N VPN Firewall versions prior to 1.2.2.1 are affected. RV130W Wireless-N Multifunction VPN Router versions prior to 1.0.3.45 are affected. RV215W Wireless-N VPN Router versions prior to 1.3.1.1 are affected.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 19, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco rv110w firmware | < 1.2.2.1 |
CPE
Remediation
| |
| cisco rv110w | All versions |
CPE
Remediation
| |
| cisco rv130w firmware | < 1.0.3.45 |
CPE
Remediation
| |
| cisco rv130w | All versions |
CPE
Remediation
| |
| cisco rv215w firmware | < 1.3.1.1 |
CPE
Remediation
| |
| cisco rv215w | All versions |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 5, 2020 | Modified Analysis | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Sep 2, 2019 | CVE Modified | [email protected] |
| Jun 4, 2019 | CVE Modified | [email protected] |
| May 13, 2019 | Modified Analysis | [email protected] |
| Apr 28, 2019 | CVE Modified | [email protected] |
| Apr 15, 2019 | CVE Modified | [email protected] |
| Apr 15, 2019 | CVE Modified | [email protected] |
| Mar 1, 2019 | Initial Analysis | [email protected] |
| Mar 1, 2019 | CVE Modified | [email protected] |