OS Command Injection Vulnerability in Cisco RV130 and RV110W Routers
CVE-2026-24700

7.2HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
8 July 2026

What is CVE-2026-24700?

An OS command injection vulnerability exists in the start_lltd() function of the 'rc' binary in Cisco RV130/RV130W and RV110W routers. The vulnerability is due to improper sanitization of the machine_name configuration parameter. This flaw may allow an authenticated remote attacker to execute arbitrary OS commands with root privileges, thereby potentially compromising the device and its network.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.