CVE-2026-24699Active Exploitation(cisco / rv110w)

MEDIUMCVSS 7.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for cisco rv110w systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rv110w
  • rv110w_firmware
  • rv130
  • rv130_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
rv110wrv110w_firmwarerv130rv130_firmwarerv130wrv130w_firmware

4 versions affected across 6 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-08: 1Active Exploitation · 2026-07-08: 1Technical Details · 2026-07-08: 107-08
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    ⚠️ HIGH — CVE-2026-24699 An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with … ⚡ Exploit in the wild Full analysis → https://sec.kaitan.id/cves/CVE-2026-24699 #Cisco #CyberSecurity #InfoSec

    Post summary

    Cisco RV130/RV130W hosts a high‑severity OS command injection flaw (CVE‑2026‑24699) that is reportedly being actively exploited, with detailed technical information available via the provided link. No patch or mitigation is mentioned.

    0000051
    84 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
HWciscorv110w---
OSciscorv110w_firmware1.2.2.5--
OSciscorv110w_firmware1.2.2.8--
HWciscorv130---
OSciscorv130_firmware1.0.3.55--
HWciscorv130w---
OSciscorv130w_firmware1.0.3.55--

Explore more