Description
An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Published: 2026-07-08
Score: 7.2 High
EPSS: 1.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw is present in the start_lltd() function of the rc binary on specific Cisco RV130, RV130W, and RV110W routers. The machine_name configuration parameter is not properly sanitized, allowing an authenticated remote attacker to execute arbitrary operating system commands with root privileges. The weakness is classified as CWE-78.

Affected Systems

Cisco RV130 and RV130W models running firmware 1.0.3.55, and Cisco RV110W models running firmware 1.2.2.5 or 1.2.2.8 are affected.

Risk and Exploitability

The vulnerability has a CVSS base score of 7.2, indicating high severity, and an EPSS score of 2%, reflecting a low but non‑negligible exploitation probability. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires the attacker to be authenticated to the router’s administrative interface, implying a network‑based attack vector. Successful exploitation grants the attacker full root-level control, enabling complete compromise of the device and potential lateral movement within the network.

Generated by OpenCVE AI on July 26, 2026 at 18:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest Cisco release that contains the patch for the command injection in the rc binary.
  • Restrict administrative access to the router by configuring firewall or ACL rules to allow only trusted IP addresses, thereby limiting exposure to authenticated attacks.
  • If possible, remove or set the machine_name parameter to a safe, non‑injectable value to reduce the injection surface.

Generated by OpenCVE AI on July 26, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/RV110 Routers Allowing Root‑Level Execution

Fri, 24 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/110 Router Firmware via Unsanitized machine_name Parameter

Tue, 21 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/110 Router Firmware via Unsanitized machine_name Parameter

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Untrusted Machine Name Parameter Allows Command Injection on Cisco RV130/RV130W and RV110W Routers

Wed, 15 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Untrusted Machine Name Parameter Allows Command Injection on Cisco RV130/RV130W and RV110W Routers

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130 and RV110W Routers

Sun, 12 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130 and RV110W Routers

Sat, 11 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection via Machine_Name Parameter in Cisco RV Routers Firmware 1.x

Fri, 10 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection via Machine_Name Parameter in Cisco RV Routers Firmware 1.x

Fri, 10 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/RV130W and RV110W Routers

Thu, 09 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/RV130W and RV110W Routers

Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-08T15:49:09.772Z

Reserved: 2026-01-23T00:00:00.000Z

Link: CVE-2026-24700

cve-icon Vulnrichment

Updated: 2026-07-08T15:48:54.271Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T18:45:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')