HIGHCVSS 7.21% EPSS
An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Published 2026-07-08 · last modified 2026-07-10
| Vendor | Product |
|---|---|
| cisco | rv110w_firmware |
| cisco | rv130_firmware |
| cisco | rv130w_firmware |
Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.