OS Command Injection Vulnerability in Cisco RV130/RV130W and RV110W Routers
CVE-2026-24697
7.2HIGH
What is CVE-2026-24697?
An OS command injection vulnerability exists in the start_bonjour() function of the 'rc' binary within Cisco RV130/RV130W and RV110W routers. This security weakness is rooted in improper sanitization of the wan_hostname configuration parameter, which could be exploited by an authenticated remote attacker. Successful exploitation may lead to the execution of arbitrary OS commands with root privileges, potentially compromising the integrity and confidentiality of the affected devices.