CVE-2026-24700
rv130 firmware, rv130
An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
- CVSS
- 7.2
- EPSS
- 1.52% 72.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.09