Remote Command Injection in Cisco IOS XE Software
CVE-2025-20334

8.8HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
24 September 2025

Badges

👾 Exploit Exists

What is CVE-2025-20334?

A vulnerability exists in the HTTP API of Cisco IOS XE Software, allowing remote attackers to inject arbitrary commands with root privileges into the operating system. This security flaw arises from inadequate input validation. An attacker with administrative access can exploit this by executing an API call with specially crafted input. Furthermore, an unauthenticated user may trick a legitimate logged-in user into clicking a malicious link, leading to exploitation. If successful, this could result in the unauthorized execution of commands at the root level, posing a significant risk to the system's integrity.

Affected Version(s)

Cisco IOS XE Software 17.9.5

Cisco IOS XE Software 17.9.5a

Cisco IOS XE Software 17.9.5b

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20334 : Remote Command Injection in Cisco IOS XE Software