CVE-2026-24698
Description
An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Summary dbcve.org
OS command injection vulnerability in the httpd binary on Cisco RV130/RV130W and RV110W routers. The model_name configuration parameter is not sanitized before being used in a system call within the save_syslog_to_file() function, allowing authenticated remote attackers to inject arbitrary OS commands that execute with root privileges.
Mitigation
Apply Cisco firmware updates for RV130/RV130W (1.0.3.55) and RV110W (1.2.2.5/1.2.2.8) when available. Until patched, restrict remote management access to trusted IP addresses only or disable the web interface on WAN-facing interfaces.