Description
An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Published: 2026-07-08
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw exists in the start_bonjour() routine of the "rc" daemon on certain Cisco RV routers. The flaw arises from improper sanitization of the wan_hostname configuration which could allow an authenticated remote attacker to execute arbitrary operating‑system commands. A successful exploitation would grant the attacker root‑level control over the device, compromising network infrastructure and any hosts protected by the router.

Affected Systems

The issue appears in Cisco RV130 and RV130W routers running firmware version 1.0.3.55, and in RV110W routers running firmware versions 1.2.2.5 or 1.2.2.8. Only these specific firmware releases are known to be vulnerable; newer releases are not listed as affected.

Risk and Exploitability

The CVSS v3 score of 7.2 indicates high severity. The EPSS score of < 1% indicates a non‑zero probability of exploitation, and the vulnerability’s KEV catalog status shows it is not listed, suggesting no known widespread exploitation yet. The flaw requires remote authentication, so a legitimate management session or a compromised admin credential provides the necessary access. Once authenticated, an attacker can inject any command, leading to full system compromise.

Generated by OpenCVE AI on July 26, 2026 at 18:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the‑injection flaw; consult Cisco’s official release notes for the affected models.
  • If an immediate firmware upgrade is not possible, block or restrict remote access to the router’s administrative interface, for example by applying firewall rules that limit inbound connections to trusted IP addresses only.
  • As a temporary workaround, change the wan_hostname configuration to a simple string without special characters, or disable the start_bonjour functionality if the firmware permits; this reduces the risk until a patch can be applied.

Generated by OpenCVE AI on July 26, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV Routers Grants Root Access

Fri, 24 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Authenticated OS Command Injection in Cisco RV Router Firmware

Tue, 21 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Authenticated OS Command Injection in Cisco RV Router Firmware

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/110 Router Firmware

Wed, 15 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/110 Router Firmware

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV Routers' WAN Hostname Setting

Sun, 12 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV Routers' WAN Hostname Setting

Sat, 11 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Cisco RV Router OS Command Injection via wan_hostname

Fri, 10 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Cisco RV Router OS Command Injection via wan_hostname

Fri, 10 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Authenticated OS Command Injection via WAN Hostname in Cisco RV Routers

Thu, 09 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Authenticated OS Command Injection via WAN Hostname in Cisco RV Routers

Wed, 08 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-08T15:47:34.791Z

Reserved: 2026-01-23T00:00:00.000Z

Link: CVE-2026-24697

cve-icon Vulnrichment

Updated: 2026-07-08T15:47:07.862Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T18:45:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')