CVE-2026-24698
published 2026-07-08CVE-2026-24698: An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and…
PriorityP355high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.96%
57.3th percentile
An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | rv110w_firmware | — | — |
| cisco | rv110w_firmware | — | — |
| cisco | rv130_firmware | — | — |
| cisco | rv130w_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco RV130/RV130W/RV110W 1.0.3.55/1.2.2.5/1.2.2.8 Syslog Configuration save_syslog_to_file model_name os command injection
vuldb·2026-07-12·CVSS 7.2
CVE-2026-24698 [HIGH] Cisco RV130/RV130W/RV110W 1.0.3.55/1.2.2.5/1.2.2.8 Syslog Configuration save_syslog_to_file model_name os command injection
A vulnerability classified as very critical was found in Cisco RV130, RV130W and RV110W 1.0.3.55/1.2.2.5/1.2.2.8. This impacts the function save_syslog_to_file of the component Syslog Configuration Handler. Such manipulation of the argument model_name leads to os command injection.
This vulnerability is referenced as CVE-2026-24698. It is possible to launch the attack remotely. No exploit is available.
GHSA
An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8
ghsa_unreviewed·2026-07-08
CVE-2026-24698 [HIGH] CWE-78 An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8
An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-08
Published