CVE-2026-24700: OS Command Injection
An OS command injection vulnerability exists in the startlltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machinename configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco RV130/RV130Wto a version that resolves this vulnerability.Fixed in 1.0.3.55 - Upgrade
Upgrade
Cisco RV110Wto a version that resolves this vulnerability.Fixed in 1.2.2.5 / 1.2.2.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24700?
CVE-2026-24700 has a high severity rating of 7.2 based on the CVSS score.
How do I fix CVE-2026-24700?
To fix CVE-2026-24700, update the firmware on affected Cisco RV110W and RV130/RV130W routers to the latest version.
What systems are affected by CVE-2026-24700?
The affected systems include Cisco RV110W routers with firmware versions 1.2.2.5 and 1.2.2.8, and Cisco RV130/RV130W routers with firmware version 1.0.3.55.
What type of vulnerability is CVE-2026-24700?
CVE-2026-24700 is an OS command injection vulnerability that occurs during the execution of the start_lltd() function.
What impact does CVE-2026-24700 have?
CVE-2026-24700 could allow authenticated remote attackers to execute arbitrary OS commands, leading to potential system compromise.