Impact
An OS command injection flaw exists in the sub_34984() function of the rc binary on Cisco RV130 and RV130W routers running firmware 1.0.3.55 and on RV110W routers with firmware 1.2.2.5 or 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which permits an authenticated remote attacker to inject arbitrary OS commands that are executed with root privileges, fully compromising the router’s operating system.
Affected Systems
Cisco RV130 and RV130W routers with firmware 1.0.3.55, and Cisco RV110W routers with firmware versions 1.2.2.5 and 1.2.2.8 are affected. Administrators must verify the router model and firmware version to ascertain impact.
Risk and Exploitability
The vulnerability has a CVSS score of 7.2 and an EPSS score of less than 1%, indicating a very low probability of exploitation. It is not listed in CISA’s KEV catalog. Exploitation requires authenticated remote access to the router’s management interface, and an attacker can submit malicious lan_ipv6_prefixlen values which the rc binary processes without proper escaping, resulting in arbitrary shell command execution as root.
OpenCVE Enrichment