7/15/2026 • Security
Even Cisco's Small-Business Routers Reach a Dead End: An EOL Security Reminder
A fresh cluster of root-level flaws in Cisco's old RV small-business routers — and an 18-year-old Cisco flaw now confirmed as actively exploited — are a timely reminder about end-of-life gear. This one's a heads-up, not a sales pitch.
A heads-up, not a sales pitch
We keep an eye on security advisories that affect the kind of gear our customers actually run. Every so often something lands that's worth passing on — not because we're trying to sell you anything, but because you'd genuinely want to know. This is one of those.
Two things crossed the wire in the past week, and together they tell a single, useful story about end-of-life networking gear. The honest takeaway is one we'll happily apply to our own favourite brands too: a device is only as safe as the support still standing behind it.
What happened, in plain English
First — four new root-level flaws in Cisco's old RV routers. On 8 July 2026, four separate vulnerabilities were disclosed in Cisco's RV130, RV130W and RV110W small-business routers (CVE-2026-24697, -24698, -24699 and -24700). They're all the same class of bug — OS command injection, each rated CVSS 7.2 (High) — and each one lets an attacker run commands on the device with full root privileges through a different unsanitised setting (the hostname, model name, an IPv6 setting, and so on).
There's an important bit of honesty here: these four require the attacker to be authenticated first — they're not a "walk straight in from the internet" flaw on their own. But here's the catch that matters: these routers are end-of-life. Cisco has flagged them "unsupported," which means no patch is coming — ever. An internet-exposed router with weak or default credentials, or paired with one of this line's well-documented earlier flaws, is exactly how an attacker gets that first foothold. And once they're in, there's no fix to apply.
Second — an 18-year-old Cisco flaw is now confirmed as actively exploited. On 13 July 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2008-4128 to its Known Exploited Vulnerabilities (KEV) catalogue. That's a cross-site request forgery flaw in the web management interface of the old Cisco 871 router (Cisco IOS 12.4). On paper it's a modest-scoring bug that needs a logged-in admin to be tricked into visiting a malicious page. But being added to the KEV list means one thing plainly: attackers are using it right now.
Notice the date on that one. 2008. An 18-year-old flaw in a small-office router is being actively exploited in 2026. That's the whole point.
Why these two stories are really the same story
Put them side by side and the lesson writes itself: old, unsupported networking gear doesn't fade quietly into retirement — it becomes a target.
- The RV routers show what happens when new flaws are found in old gear: they simply never get fixed.
- The 18-year-old Cisco 871 flaw shows that attackers actively hunt for this forgotten equipment years — decades — after everyone stopped thinking about it.
Neither of these is a reason to panic. Very few Australian businesses are running these exact models today. The reason we're flagging them is the pattern, because the pattern absolutely does apply to gear that's still humming away in comms cupboards around the country: the moment a device stops receiving security updates, the clock starts ticking, and there's no way to wind it back.
The honest bit: no vendor is immune — including the ones we like
We specialise in Cisco Meraki, so it would be easy to spin this as "Cisco old, Meraki good." That's not the honest read, and we'd rather be straight with you.
These flaws are in Cisco's own older small-business lines. Good vendors ship bugs too — all of them do. What actually protects you isn't the badge on the box; it's whether the device is still supported and still getting fixes. An end-of-life Cisco router and an end-of-life anything-else are in the same boat: no patches, no safety net.
That's the same point we made recently about a Tenda router backdoor with no patch and a silent vendor, and about old routers and NAS being quietly hijacked. Different brands, same underlying truth.
Where the type of platform genuinely helps is the lifecycle. Cloud-managed gear — including the Meraki MX line we tend to recommend — has two advantages that are relevant here: fixes are pushed automatically while the device is supported (no one has to remember to log in and patch), and it has clear, published end-of-support dates you can plan around instead of being caught out. We've written about both — why a cloud-managed firewall keeps improving after you buy it and how to plan an end-of-support refresh calmly. That's not a pitch; it's just the part of the story that's genuinely different.
What we'd suggest you actually do
No urgency, no upsell — just a sensible tidy-up you can do at your own pace:
- Take five minutes to see what's at your edge. Walk to the comms cupboard and look at the router and firewall doing the work. Note the make, model and rough age.
- Check whether it's still supported. A quick search for "[your model] end of life" usually tells you. If the manufacturer no longer issues security updates for it, treat it as living on borrowed time.
- If you're running one of the named models — Cisco RV130, RV130W, RV110W, or an old Cisco 871 — don't leave its management interface reachable from the internet. Disable remote/web administration, and plan a replacement rather than relying on workarounds.
- Cover the basics regardless of brand: change default credentials, turn on multi-factor authentication where you can, and never expose an admin page to the open internet.
- When it is time to replace something, weigh the whole picture — not just the sticker price, but whether the vendor will still be patching it in a few years. That's the part that quietly matters most.
The friendly takeaway
This isn't a "the sky is falling" post. It's a reminder that the least glamorous device in your office — the router — is also the most privileged, and it's only trustworthy for as long as someone is still fixing it. Old Cisco gear, old anything gear: once the updates stop, it slowly turns from an asset into a liability, and attackers are patient enough to wait.
If you ever want a second pair of eyes on what's sitting at the edge of your network — no obligation, no hard sell — we're always happy to help you work out whether it's still safe or quietly overdue for retirement. That's what neighbours in the trade are for.
References
- CISA — CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2008-4128, 13 July 2026)
- NVD — CVE-2008-4128 (Cisco IOS 12.4 / 871 router CSRF)
- NVD — CVE-2026-24697, CVE-2026-24698, CVE-2026-24699, CVE-2026-24700 (Cisco RV130/RV130W/RV110W command injection)