OS Command Injection Vulnerability in Cisco RV130 and RV110W Routers
CVE-2026-24698

7.2HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
8 July 2026

What is CVE-2026-24698?

An OS command injection vulnerability in Cisco's RV130/RV130W and RV110W routers allows authenticated remote attackers to exploit the save_syslog_to_file() function. Due to the improper sanitization of the model_name configuration parameter, attackers can execute arbitrary OS commands with root privileges, potentially compromising the device's integrity and access to network environments.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.