CVE-2026-24700: Cisco RV130/RV110W OS Command Injection—Admin Authentication Required
A command injection flaw in Cisco small business routers allows authenticated administrators to execute arbitrary commands with root-level privileges by injecting malicious input into the machine name configuration field. An attacker with valid admin credentials can manipulate this parameter to break out of the intended configuration context and run arbitrary OS commands on the affected router.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.2 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-78
- Affected products
- 7 configuration(s)
- Published / Modified
- 2026-07-08 / 2026-07-10
NVD description (verbatim)
An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-24700 is an OS command injection vulnerability (CWE-78) in the start_lltd() function within the rc binary of Cisco RV130, RV130W, and RV110W routers. The machine_name configuration parameter undergoes insufficient input validation, permitting authenticated remote attackers to inject shell metacharacters and execute arbitrary commands with root privileges. The vulnerability affects RV130/RV130W running firmware 1.0.3.55 and RV110W running firmware 1.2.2.5 or 1.2.2.8.
Business impact
Compromise of these routers exposes internal networks to direct control by a malicious insider or an attacker who has obtained valid administrative credentials. Since these devices sit at the network perimeter, successful exploitation enables lateral movement into the enterprise network, potential data exfiltration, network reconnaissance, and deployment of persistent backdoors. For organizations relying on these models for branch office or remote site connectivity, this represents a critical trust boundary violation.
Affected systems
Cisco RV130 routers with firmware version 1.0.3.55, Cisco RV130W with firmware 1.0.3.55, and Cisco RV110W with firmware versions 1.2.2.5 or 1.2.2.8 are confirmed vulnerable. These are small business-grade routers commonly deployed in SMB and branch office environments. Administrators should verify their running firmware versions urgently against these specific builds.
Exploitability
Exploitation requires valid administrative credentials—the attacker must already be authenticated to the router management interface. This significantly reduces the immediate risk from untargeted external attacks, but substantially elevates risk in scenarios involving compromised admin accounts, insider threats, or lateral movement from a compromised internal network segment. No network-based unauthenticated attack path exists. The attack surface is primarily the web-based or SSH administrative interface.
Remediation
Organizations running affected firmware versions must apply vendor-supplied patches as soon as they become available. Interim mitigations include restricting administrative access to trusted networks only, implementing network segmentation to limit router management traffic, disabling remote administration features if not required, and enforcing strong, unique credentials for all administrative accounts. Monitor authentication logs for suspicious login attempts or unusual configuration changes.
Patch guidance
Contact Cisco support or consult the vendor security advisory for patched firmware versions applicable to your specific router model and current firmware branch. Verify the patch version against the official Cisco security advisory before deployment. Test patches in a non-production environment first, as router firmware updates can temporarily disrupt network connectivity. Coordinate patch deployment during approved maintenance windows.
Detection guidance
Monitor router access logs for failed authentication attempts targeting the admin interface. Watch for configuration changes involving the machine_name parameter, particularly those containing shell metacharacters (backticks, pipes, semicolons, $() constructs). Enable verbose logging on administrative actions if supported. Network-based detection is limited without privileged access to the management interface; focus detection efforts on authentication anomalies and post-exploitation behavioral indicators such as unexpected outbound connections from the router or unusual process activity if syslog forwarding is enabled.
Why prioritize this
While the CVSS score of 7.2 reflects a high-severity vulnerability, the requirement for prior authentication moderates the immediate blast radius. However, prioritization should remain high because: (1) these routers are security perimeters; (2) root-level command execution enables complete device compromise; (3) affected organizations typically operate multiple units; and (4) insider threat or credential compromise scenarios make this practically exploitable in real environments. Smaller organizations managing these devices may lack robust logging, making detection difficult post-breach.
Risk score, explained
The CVSS 3.1 score of 7.2 (HIGH) reflects: Network-accessible attack vector (AV:N) via the management interface, low attack complexity (AC:L) once authenticated, high privilege requirement (PR:H) limiting unauthenticated exploitation, no user interaction needed (UI:N), unchanged scope (S:U), and high impact across confidentiality, integrity, and availability (C:H/I:H/A:H). The authentication prerequisite prevents a Critical rating but does not diminish the severity of what an authenticated attacker can accomplish.
Frequently asked questions
Do we need to patch if we have strong firewall rules restricting router admin access?
Firewall restrictions significantly reduce exposure but do not eliminate risk entirely. Insider threats, compromised internal systems, or lateral movement from other compromised devices could still lead to router admin access. Patching remains essential; firewall rules are a complementary control, not a substitute.
What is the practical attack scenario for an authenticated user?
The primary concern is compromised administrative credentials (through phishing, password reuse, or malware) or a disgruntled insider with admin access. An attacker with valid credentials can alter the machine name to inject commands—for example, setting it to `test; malicious_command #` to execute arbitrary code with root privileges. The command executes when the start_lltd() function processes this parameter.
Will this vulnerability be added to the CISA KEV catalog?
At the time of publication, this vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, KEV status can change as threats evolve. Continue to monitor CISA advisories and assume higher risk if the status changes.
Can we detect if someone has exploited this vulnerability on our routers?
Detection is challenging without robust logging infrastructure. Check for recent configuration changes involving the machine_name field, review authentication logs for suspicious admin logins, and monitor syslog for unexpected process execution. Many small routers have limited logging; consider deploying centralized logging if possible and enabling maximum verbosity on administrative events.
This analysis is for informational purposes and is based on publicly disclosed vulnerability data as of the publication date. Specific patch versions, patch release dates, and remediation timelines should be verified directly with Cisco's official security advisories and support channels. Organizations are responsible for assessing their own exposure, testing patches in their environment, and coordinating remediation according to their change management and risk policies. SEC.co makes no warranty regarding the completeness or timeliness of this information. Always consult authoritative vendor sources before making security decisions. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-24697HIGHCisco RV130/RV110W Command Injection Vulnerability
- CVE-2026-24698HIGHCisco RV130/RV110W Command Injection
- CVE-2026-24699HIGHCisco RV130/RV110W OS Command Injection Vulnerability
- CVE-2025-41265HIGHWaterfall WF-500 TX Host OS Command Injection (CVSS 7.2)
- CVE-2025-41266HIGHWaterfall WF-500 TX Host Command Injection Vulnerability Analysis
- CVE-2025-41267HIGHWaterfall WF-500 TX Host Command Injection Vulnerability
- CVE-2025-41279HIGHOS Command Injection in Waterfall WF-500 RX Host Administration WebUI
- CVE-2025-41281HIGHWaterfall WF-500 OS Command Injection