OS Command Injection Vulnerability in Cisco RV130/RV130W and RV110W Routers
CVE-2026-24699
7.2HIGH
What is CVE-2026-24699?
An OS command injection vulnerability has been identified in the 'sub_34984()' function of the 'rc' binary within Cisco RV130/RV130W and RV110W routers. This issue arises from inadequate sanitization of the 'lan_ipv6_prefixlen' configuration parameter, potentially allowing an authenticated remote attacker to execute arbitrary OS commands at the root level. This vulnerability emphasizes the importance of robust input validation practices in network device firmware.