CVE-2026-24700
published 2026-07-08CVE-2026-24700: An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers…
PriorityP356high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.28%
66.7th percentile
An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | rv110w_firmware | — | — |
| cisco | rv110w_firmware | — | — |
| cisco | rv130_firmware | — | — |
| cisco | rv130w_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco RV130/RV110W 1.0.3.55/1.2.2.5/1.2.2.8 LLTD Configuration start_lltd machine_name os command injection
vuldb·2026-07-12·CVSS 7.2
CVE-2026-24700 [HIGH] Cisco RV130/RV110W 1.0.3.55/1.2.2.5/1.2.2.8 LLTD Configuration start_lltd machine_name os command injection
A vulnerability, which was classified as very critical, was found in Cisco RV130 and RV110W 1.0.3.55/1.2.2.5/1.2.2.8. Affected by this vulnerability is the function start_lltd of the component LLTD Configuration Handler. Executing a manipulation of the argument machine_name can lead to os command injection.
This vulnerability is tracked as CVE-2026-24700. The attack can be launched remotely. No exploit exists.
GHSA
An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8.
ghsa_unreviewed·2026-07-08
CVE-2026-24700 [HIGH] CWE-78 An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8.
An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-08
Published