Impact
An OS command injection flaw exists in the start_bonjour() routine of the "rc" daemon on certain Cisco RV routers. The flaw arises from improper sanitization of the wan_hostname configuration which could allow an authenticated remote attacker to execute arbitrary operating‑system commands. A successful exploitation would grant the attacker root‑level control over the device, compromising network infrastructure and any hosts protected by the router.
Affected Systems
The issue appears in Cisco RV130 and RV130W routers running firmware version 1.0.3.55, and in RV110W routers running firmware versions 1.2.2.5 or 1.2.2.8. Only these specific firmware releases are known to be vulnerable; newer releases are not listed as affected.
Risk and Exploitability
The CVSS v3 score of 7.2 indicates high severity. The EPSS score of < 1% indicates a non‑zero probability of exploitation, and the vulnerability’s KEV catalog status shows it is not listed, suggesting no known widespread exploitation yet. The flaw requires remote authentication, so a legitimate management session or a compromised admin credential provides the necessary access. Once authenticated, an attacker can inject any command, leading to full system compromise.
OpenCVE Enrichment