Description
An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Published: 2026-07-08
Score: 7.2 High
EPSS: 1.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw is present in the start_lltd() function of the rc binary on specific Cisco RV130, RV130W, and RV110W routers. The machine_name configuration parameter is not properly sanitized, allowing an authenticated remote attacker to execute arbitrary operating system commands with root privileges. The weakness is classified as CWE-78.

Affected Systems

Cisco RV130 and RV130W models running firmware 1.0.3.55, and Cisco RV110W models running firmware 1.2.2.5 or 1.2.2.8 are affected.

Risk and Exploitability

The vulnerability has a CVSS base score of 7.2, indicating high severity, and an EPSS score of 2%, reflecting a low but non‑negligible exploitation probability. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires the attacker to be authenticated to the router’s administrative interface, implying a network‑based attack vector. Successful exploitation grants the attacker full root‑level control, enabling complete compromise of the device and potential lateral movement within the network.

Generated by OpenCVE AI on July 31, 2026 at 14:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest Cisco release that contains the patch for the command injection in the rc binary.
  • Restrict administrative access to the router by configuring firewall or ACL rules to allow only trusted IP addresses, thereby limiting exposure to authenticated attacks.
  • If possible, remove or set the machine_name parameter to a safe, non‑injectable value to reduce the injection surface.

Generated by OpenCVE AI on July 31, 2026 at 14:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/RV110 Routers Allowing Root‑Level Execution

Sun, 26 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/RV110 Routers Allowing Root‑Level Execution

Fri, 24 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/110 Router Firmware via Unsanitized machine_name Parameter

Tue, 21 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/110 Router Firmware via Unsanitized machine_name Parameter

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Untrusted Machine Name Parameter Allows Command Injection on Cisco RV130/RV130W and RV110W Routers

Wed, 15 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Untrusted Machine Name Parameter Allows Command Injection on Cisco RV130/RV130W and RV110W Routers

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130 and RV110W Routers

Sun, 12 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130 and RV110W Routers

Sat, 11 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection via Machine_Name Parameter in Cisco RV Routers Firmware 1.x

Fri, 10 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection via Machine_Name Parameter in Cisco RV Routers Firmware 1.x

Fri, 10 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/RV130W and RV110W Routers

Thu, 09 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/RV130W and RV110W Routers

Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
References

Subscriptions

Cisco Rv110w Rv110w Firmware Rv130 Rv130 Firmware Rv130w Rv130w Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-08T15:49:09.772Z

Reserved: 2026-01-23T00:00:00.000Z

Link: CVE-2026-24700

cve-icon Vulnrichment

Updated: 2026-07-08T15:48:54.271Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-08T15:16:27.047

Modified: 2026-07-10T17:49:52.123

Link: CVE-2026-24700

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T14:15:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')