Junglewise Threat Intelligence

CVE-2026-24699: Cisco RV Series Routers OS command injection in rc binary

CVE-2026-24699 · Severity: info · CVSS 8.8 · Published 2026-07-08

Technologies: Cisco RV110W Wireless-N VPN Firewall. Vendors: Cisco.

Executive brief

A security vulnerability exists in several Cisco small business routers, including the RV110W, RV130, and RV130W models. These devices are used to provide networking and firewall services for small offices. An attacker with administrative access could exploit this flaw to take full control of the router, potentially leading to permanent device failure or the ability to monitor network traffic.

Technical details

An OS command injection vulnerability exists in the 'rc' binary of affected Cisco routers within the sub_34984() function. The vulnerability is caused by a failure to sanitize the 'lan_ipv6_prefixlen' configuration parameter retrieved from NVRAM before passing it to a system() call via sprintf(). An authenticated remote attacker can inject shell metacharacters (e.g., '$(reboot)') into this parameter to execute arbitrary commands with root privileges. Because the 'rc' process handles core system initialization, malicious payloads can cause persistent execution across reboots or result in a permanent 'brick' state requiring hardware-level recovery.

Affected products

  • Cisco RV130 VPN Router 1.0.3.55
  • Cisco RV130W Wireless-N VPN Router 1.0.3.55
  • Cisco RV110W Wireless-N VPN Firewall 1.2.2.5, 1.2.2.8

Timeline

  • 2026-07-08: disclosed: Initial disclosure via GitHub and NVD publication

References

Related threats