CVE-2026-24697: Cisco RV130/RV110W Command Injection Vulnerability
Cisco's small-business routers (RV130, RV130W, and RV110W) contain a command injection flaw in their configuration handling. An attacker with administrative access to the device can manipulate the WAN hostname setting to inject and execute arbitrary operating system commands with root-level privileges. This is a serious post-authentication vulnerability because once an attacker has logged in—whether through credential compromise, phishing, or insider threat—they can escalate to full system control.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.2 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-78
- Affected products
- 7 configuration(s)
- Published / Modified
- 2026-07-08 / 2026-07-10
NVD description (verbatim)
An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability resides in the start_bonjour() function within the rc binary on affected Cisco routers. The wan_hostname configuration parameter undergoes insufficient input validation before being passed to OS command execution contexts. The lack of proper sanitization allows shell metacharacters and command separators to be interpreted rather than escaped, enabling arbitrary command injection. The vulnerability requires prior authentication (high privilege required per CVSS vector) but results in unauthenticated-equivalent impact once exploited, as the injected commands execute with root privileges.
Business impact
Organizations deploying these Cisco small-business routers as edge network devices face significant risk if their device credentials are compromised. A successful exploit grants attackers root access to the router, enabling them to intercept, redirect, or exfiltrate network traffic; establish persistent backdoors; launch lateral attacks into the internal network; or cause denial of service. For businesses relying on these routers for remote office, branch, or small-site connectivity, compromise could disrupt critical operations and create a foothold for broader infrastructure attacks.
Affected systems
The vulnerability affects Cisco RV130 and RV130W routers running firmware version 1.0.3.55, and Cisco RV110W routers running firmware versions 1.2.2.5 or 1.2.2.8. Organizations should verify their exact device models and current firmware versions against these specific releases. If your deployment includes any of these models, immediate inventory and vulnerability assessment is warranted.
Exploitability
Exploitation requires an authenticated attacker with administrative credentials or sufficient privilege to modify the device's WAN hostname configuration. This means the attack cannot be launched by an unauthenticated remote user on the internet; however, the authenticated requirement is the primary barrier, not a true mitigation. In environments where router credentials are weak, reused, or have been compromised through phishing or credential stuffing, the practical exploitability is moderate to high. No public exploits are currently tracked in the known exploited vulnerabilities (KEV) catalog.
Remediation
Cisco has not yet released official patched firmware versions in the provided data. Organizations must contact Cisco directly or monitor the official Cisco Security Advisories page for firmware updates addressing this vulnerability. In the interim, implement strong access controls: disable remote administration unless absolutely necessary, enforce strong, unique credentials for router accounts, restrict administrative access to trusted IP ranges, and monitor configuration changes for suspicious modifications to network parameters.
Patch guidance
Verify the availability of patched firmware versions from Cisco's official advisory for your specific router model (RV130, RV130W, or RV110W). Firmware updates should be tested in a non-production environment before deployment. Coordinate patching during maintenance windows to minimize network disruption. After patching, verify that configuration settings—particularly the WAN hostname—have not been altered by unauthorized parties.
Detection guidance
Monitor router configuration logs and syslog output for unexpected changes to the wan_hostname parameter or the start_bonjour() function behavior. Look for administrative login attempts from unusual IP addresses or at odd times. Inspect running processes on the router (via SSH or console access if available) for unexpected child processes spawned by the rc binary. Network-level detection is difficult because the injected commands execute locally on the device; endpoint monitoring of the router itself is the most effective approach. Implement alerting on failed and successful administrative authentications.
Why prioritize this
This vulnerability merits near-term action because it enables complete system compromise once authentication is obtained, affects network edge devices that are critical choke points, and the barrier to exploitation (valid credentials) is often overcome through credential compromise campaigns. Although not currently in the KEV catalog, the severity and attack surface make this a priority for organizations using these specific Cisco models. Prioritize patching ahead of less critical firmware updates.
Risk score, explained
The CVSS 3.1 score of 7.2 (HIGH) reflects the combination of high impact (confidentiality, integrity, and availability all compromised at the system level) and the requirement for high-privilege authentication. The network-accessible attack vector acknowledges that the initial foothold must come via network login, but once authenticated, the injected commands run with full system privileges. The score appropriately reflects that this is a serious post-authentication vulnerability but not an unauthenticated remote code execution.
Frequently asked questions
Do we need to patch if our routers are behind a firewall with restricted administrative access?
Yes. Restricting administrative access reduces the attack surface, but does not eliminate the vulnerability. Insider threats, credential compromise, or misconfigured access rules could still allow an attacker to reach the administrative interface. Defense-in-depth requires both network segmentation and timely patching.
What should we do while waiting for Cisco to release a patch?
Immediately audit your router credentials for complexity and uniqueness; disable remote administration if not needed; restrict administrative access to a whitelist of trusted IP addresses; implement RADIUS or similar centralized authentication if available on your routers; enable detailed logging and monitoring for configuration changes; and escalate this to your change management process to prioritize patching once updates become available.
Could an attacker inject commands without logging in?
No. This vulnerability requires prior authentication with administrative or equivalent privilege. An unauthenticated attacker on the internet cannot exploit this flaw directly. However, compromised credentials—through phishing, weak passwords, credential reuse, or insider access—are common enough that this should not be treated as a low-risk vulnerability.
Does this affect our cloud infrastructure or only on-premises routers?
This affects only the specific Cisco router hardware models listed. If you are using cloud-based routing or SD-WAN services, you may not be affected; however, if you have these Cisco models deployed at branch locations or as edge gateways, they are in scope. Verify your inventory carefully.
This analysis is based on publicly available vulnerability data and vendor information current as of the publication date. Patch availability and remediation guidance should be verified directly with Cisco's official security advisories. Exploit status and attack prevalence may change; monitor threat intelligence feeds for updates. SEC.co does not provide legal or compliance advice; consult your security and legal teams regarding regulatory obligations for remediation. This vulnerability intelligence is provided for informational purposes to aid risk assessment and prioritization; it does not constitute a guarantee of security or risk elimination. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-24698HIGHCisco RV130/RV110W Command Injection
- CVE-2026-24699HIGHCisco RV130/RV110W OS Command Injection Vulnerability
- CVE-2026-24700HIGHCisco RV130/RV110W OS Command Injection—Admin Authentication Required
- CVE-2025-41265HIGHWaterfall WF-500 TX Host OS Command Injection (CVSS 7.2)
- CVE-2025-41266HIGHWaterfall WF-500 TX Host Command Injection Vulnerability Analysis
- CVE-2025-41267HIGHWaterfall WF-500 TX Host Command Injection Vulnerability
- CVE-2025-41279HIGHOS Command Injection in Waterfall WF-500 RX Host Administration WebUI
- CVE-2025-41281HIGHWaterfall WF-500 OS Command Injection