top of page
perceptive_background_267k.jpg

An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers wit…

Published:

7 juli 2026 om 22:00:00

Alert date:

8 juli 2026 om 18:04:27

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Mobile & IoT, Zero-Day Vulnerabilities

An OS command injection vulnerability has been identified in the start_lltd() function of the 'rc' binary on Cisco RV130, RV130W, and RV110W routers. Affected firmware versions include 1.0.3.55 for RV130/RV130W and 1.2.2.5/1.2.2.8 for RV110W. The vulnerability stems from improper sanitization of the machine_name configuration parameter. An authenticated remote attacker can exploit this flaw to execute arbitrary OS commands with root privileges. This represents a high-severity risk as successful exploitation grants full system control. The vulnerability is classified as an OS command injection (CWE-78 type). Proof-of-concept details are available on GitHub. Organizations using affected Cisco small business routers should apply patches or mitigations immediately.

Technical details

Mitigation steps:

Affected products:

Cisco RV130
Cisco RV130W
Cisco RV110W

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page