Impact
An OS command injection flaw is present in the start_lltd() function of the rc binary on specific Cisco RV130, RV130W, and RV110W routers. The machine_name configuration parameter is not properly sanitized, allowing an authenticated remote attacker to execute arbitrary operating system commands with root privileges. The weakness is classified as CWE-78.
Affected Systems
Cisco RV130 and RV130W models running firmware 1.0.3.55, and Cisco RV110W models running firmware 1.2.2.5 or 1.2.2.8 are affected.
Risk and Exploitability
The vulnerability has a CVSS base score of 7.2, indicating high severity, and an EPSS score of 2%, reflecting a low but non‑negligible exploitation probability. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires the attacker to be authenticated to the router’s administrative interface, implying a network‑based attack vector. Successful exploitation grants the attacker full root-level control, enabling complete compromise of the device and potential lateral movement within the network.
OpenCVE Enrichment