CVE-2026-24698: OS Command Injection
An OS command injection vulnerability exists in the savesyslogtofile() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The modelname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24698?
CVE-2026-24698 has a high severity rating of 7.2 on the CVSS scale.
How do I fix CVE-2026-24698?
To mitigate CVE-2026-24698, users should update their Cisco RV110W or RV130/RV130W routers to the latest firmware version.
What is the risk associated with CVE-2026-24698?
CVE-2026-24698 poses a risk of OS command injection due to improper sanitization of user input in the model_name configuration parameter.
Which devices are affected by CVE-2026-24698?
CVE-2026-24698 affects Cisco RV110W routers with firmware versions 1.2.2.5 and 1.2.2.8, as well as RV130 and RV130W routers with firmware version 1.0.3.55.
What type of vulnerability is CVE-2026-24698?
CVE-2026-24698 is categorized as an OS Command Injection vulnerability that allows attackers to execute arbitrary commands on the affected routers.