top of page
perceptive_background_267k.jpg

An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W…

Published:

7 juli 2026 om 22:00:00

Alert date:

8 juli 2026 om 17:03:33

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure

An OS command injection vulnerability has been identified in the save_syslog_to_file() function within the 'httpd' binary of Cisco RV130, RV130W, and RV110W routers. The vulnerability stems from improper sanitization of the model_name configuration parameter. Affected firmware versions include RV130/RV130W firmware 1.0.3.55 and RV110W firmware 1.2.2.5 and 1.2.2.8. An authenticated remote attacker could exploit this flaw to execute arbitrary OS commands with root privileges. The vulnerability is tracked as CVE-2026-24698 and has been assigned a high criticality rating. Successful exploitation could grant full root-level control over the affected device. These router models are commonly used in small business environments, increasing the potential impact. Proof-of-concept details have been published on GitHub.

Technical details

Mitigation steps:

Affected products:

Cisco RV130
Cisco RV130W
Cisco RV110W

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page