An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 31 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV Routers Grants Root Access

Sun, 26 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV Routers Grants Root Access

Fri, 24 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Authenticated OS Command Injection in Cisco RV Router Firmware

Tue, 21 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Authenticated OS Command Injection in Cisco RV Router Firmware

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/110 Router Firmware

Wed, 15 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV130/110 Router Firmware

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV Routers' WAN Hostname Setting

Sun, 12 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Cisco RV Routers' WAN Hostname Setting

Sat, 11 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Cisco RV Router OS Command Injection via wan_hostname

Fri, 10 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Cisco RV Router OS Command Injection via wan_hostname

Fri, 10 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Authenticated OS Command Injection via WAN Hostname in Cisco RV Routers

Thu, 09 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Authenticated OS Command Injection via WAN Hostname in Cisco RV Routers

Wed, 08 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-08T15:47:34.791Z

Reserved: 2026-01-23T00:00:00.000Z

Link: CVE-2026-24697

cve-icon Vulnrichment

Updated: 2026-07-08T15:47:07.862Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-08T15:16:26.697

Modified: 2026-07-10T17:54:30.890

Link: CVE-2026-24697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T14:15:03Z

Weaknesses