Remote Command Injection in Cisco IOS XE Software
CVE-2025-20334
8.8HIGH
What is CVE-2025-20334?
A vulnerability exists in the HTTP API of Cisco IOS XE Software, allowing remote attackers to inject arbitrary commands with root privileges into the operating system. This security flaw arises from inadequate input validation. An attacker with administrative access can exploit this by executing an API call with specially crafted input. Furthermore, an unauthenticated user may trick a legitimate logged-in user into clicking a malicious link, leading to exploitation. If successful, this could result in the unauthorized execution of commands at the root level, posing a significant risk to the system's integrity.
Affected Version(s)
Cisco IOS XE Software 17.9.5
Cisco IOS XE Software 17.9.5a
Cisco IOS XE Software 17.9.5b