Junglewise Threat Intelligence

CVE-2026-24697: Cisco RV Series OS command injection in start_bonjour function

CVE-2026-24697 · Severity: info · CVSS 8.8 · Published 2026-07-08

Technologies: Cisco RV110W Wireless-N VPN Firewall. Vendors: Cisco.

Executive brief

A security vulnerability exists in several Cisco small business routers, which are used to provide network connectivity and firewall protection for offices. An authorized user could exploit this flaw to take complete control of the device by injecting malicious commands into the system configuration. This could lead to a total compromise of the network, allowing an attacker to intercept data or disrupt business operations.

Technical details

An OS command injection vulnerability exists in the 'rc' binary of Cisco RV110W, RV130, and RV130W routers. The root cause is the start_bonjour() function, which retrieves the 'wan_hostname' configuration parameter via nvram_get() and concatenates it into a system command string ('bonjour -N %s') without proper sanitization or escaping. This string is subsequently executed using the system() function. An authenticated remote attacker can exploit this by setting a malicious 'wan_hostname' containing shell metacharacters, leading to arbitrary code execution with root privileges. This affects firmware versions 1.0.3.55 for RV130/RV130W and 1.2.2.5/1.2.2.8 for RV110W.

Affected products

  • Cisco RV130 VPN Firewall 1.0.3.55
  • Cisco RV130W Wireless-N VPN Firewall 1.0.3.55
  • Cisco RV110W Wireless-N VPN Firewall 1.2.2.5, 1.2.2.8

Timeline

  • 2026-07-08: disclosed: Vulnerability report published by researcher
  • 2026-07-08: advisory: CVE-2026-24697 published

References

Related threats