Vulnerability Description
An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Rv130 Firmware | 1.0.3.55 |
| Cisco | Rv130 | - |
| Cisco | Rv130W Firmware | 1.0.3.55 |
| Cisco | Rv130W | - |
| Cisco | Rv110W Firmware | 1.2.2.5 |
| Cisco | Rv110W | - |
Related Weaknesses (CWE)
References
- https://github.com/glkfc/IoT-Vulnerability/blob/main/cisco/RV130/4/wp-en.mdThird Party Advisory
- https://github.com/glkfc/IoT-Vulnerability/blob/main/cisco/RV130/4/wp-en.mdThird Party Advisory
FAQ
What is CVE-2026-24699?
CVE-2026-24699 is a vulnerability with a CVSS score of 7.2 (HIGH). An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv...
How severe is CVE-2026-24699?
CVE-2026-24699 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-24699?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Rv130 Firmware, Cisco Rv130, Cisco Rv130W Firmware, Cisco Rv130W, Cisco Rv110W Firmware.