CVE-2026-24699
published 2026-07-08CVE-2026-24699: An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers…
PriorityP355high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.96%
57.3th percentile
An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | rv110w_firmware | — | — |
| cisco | rv110w_firmware | — | — |
| cisco | rv130_firmware | — | — |
| cisco | rv130w_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco RV130/RV110W IPv6 Configuration sub_34984 lan_ipv6_prefixlen os command injection
vuldb·2026-07-12·CVSS 7.2
CVE-2026-24699 [HIGH] Cisco RV130/RV110W IPv6 Configuration sub_34984 lan_ipv6_prefixlen os command injection
A vulnerability, which was classified as very critical, has been found in Cisco RV130 and RV110W. Affected is the function sub_34984 of the component IPv6 Configuration Handler. Performing a manipulation of the argument lan_ipv6_prefixlen results in os command injection.
This vulnerability is identified as CVE-2026-24699. The attack can be initiated remotely. There is not any exploit available.
GHSA
An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8.
ghsa_unreviewed·2026-07-08
CVE-2026-24699 [HIGH] CWE-78 An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8.
An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-08
Published