VendorsCiscorv130w_firmware1.0.3.55
Vulnerabilities

Cisco RV130W Firmware 1.0.3.55

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2021-1459
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
Published 2021-04-08 · Modified
10.0EPSS 0.030
CVE-2022-20923
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers IPSec VPN Server Authentication Bypass Vulnerability
Published 2022-09-08 · Modified
9.8EPSS 0.010
CVE-2021-1307
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
Published 2021-01-13 · Modified
9.0EPSS 0.022
CVE-2026-24700
An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Published 2026-07-08 · Analyzed
7.2EPSS 0.019
CVE-2026-24699
An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Published 2026-07-08 · Analyzed
7.2EPSS 0.015
CVE-2026-24698
An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Published 2026-07-08 · Analyzed
7.2EPSS 0.015
CVE-2026-24697
An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.
Published 2026-07-08 · Analyzed
7.2EPSS 0.015
CVE-2022-20876
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.013
CVE-2022-20877
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.013
CVE-2022-20878
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.013
CVE-2022-20875
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.013
CVE-2022-20881
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.013
CVE-2022-20882
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.013
CVE-2022-20884
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.013
CVE-2022-20885
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.013
CVE-2022-20874
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.013
CVE-2022-20889
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.013
CVE-2022-20887
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.012
CVE-2022-20888
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.012
CVE-2022-20873
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.011
CVE-2022-20910
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.011
CVE-2022-20886
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.011
CVE-2022-20883
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.011
CVE-2022-20880
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.011
CVE-2022-20879
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.011
CVE-2022-20890
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities
Published 2022-07-21 · Modified
7.2EPSS 0.010
CVE-2023-20250
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of requests that are sent to the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary code with root privileges on an affected device. To exploit this vulnerability, the attacker must have valid Administrator credentials on the affected device.
Published 2023-09-06 · Modified
7.2EPSS 0.010