Description
An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Published: 2026-07-08
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw exists in the sub_34984() function of the rc binary on Cisco RV130 and RV130W routers running firmware 1.0.3.55 and on RV110W routers with firmware 1.2.2.5 or 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which permits an authenticated remote attacker to inject arbitrary OS commands that are executed with root privileges, fully compromising the router’s operating system.

Affected Systems

Cisco RV130 and RV130W routers with firmware 1.0.3.55, and Cisco RV110W routers with firmware versions 1.2.2.5 and 1.2.2.8 are affected. Administrators must verify the router model and firmware version to ascertain impact.

Risk and Exploitability

The vulnerability has a CVSS score of 7.2 and an EPSS score of less than 1%, indicating a very low probability of exploitation. It is not listed in CISA’s KEV catalog. Exploitation requires authenticated remote access to the router’s management interface, and an attacker can submit malicious lan_ipv6_prefixlen values which the rc binary processes without proper escaping, resulting in arbitrary shell command execution as root.

Generated by OpenCVE AI on July 28, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to a version that resolves the command-injection vulnerability.
  • Restrict or disable remote management access to the router, limiting management traffic to the local network only.
  • Disable or remove the ability to modify the lan_ipv6_prefixlen configuration through the web interface if possible.

Generated by OpenCVE AI on July 28, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV Router Firmware

Wed, 22 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Command Injection via Unsanitized IPv6 Prefix Length in Cisco RV Router Firmware

Wed, 15 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Command Injection via Unsanitized IPv6 Prefix Length in Cisco RV Router Firmware

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV Series Router Firmware

Sun, 12 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV Series Router Firmware

Sat, 11 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection via lan_ipv6_prefixlen on Cisco RV Series Routers

Sat, 11 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection via lan_ipv6_prefixlen on Cisco RV Series Routers

Fri, 10 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/RV130W 'rc' Binary Allows Root Execution

Thu, 09 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/RV130W 'rc' Binary Allows Root Execution

Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-08T15:45:27.072Z

Reserved: 2026-01-23T00:00:00.000Z

Link: CVE-2026-24699

cve-icon Vulnrichment

Updated: 2026-07-08T15:44:39.971Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:30:19Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')