HIGH

CVE-2026-24698

Cisco Rv130 Firmware 2026-07-08 CVSS v3.1
CVSS
7.2

Description

An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.

Summary dbcve.org

OS command injection vulnerability in the httpd binary on Cisco RV130/RV130W and RV110W routers. The model_name configuration parameter is not sanitized before being used in a system call within the save_syslog_to_file() function, allowing authenticated remote attackers to inject arbitrary OS commands that execute with root privileges.

Mitigation

Apply Cisco firmware updates for RV130/RV130W (1.0.3.55) and RV110W (1.2.2.5/1.2.2.8) when available. Until patched, restrict remote management access to trusted IP addresses only or disable the web interface on WAN-facing interfaces.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

1.47%
Probability of exploitation in next 30 days
72.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE