Unauthorized Access in Cisco IOS Software HTTP Server Feature
CVE-2026-20125
What is CVE-2026-20125?
A vulnerability exists in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software that can allow an authenticated remote attacker to trigger a device reload. This issue arises from improper validation of user input, enabling an attacker to send malformed HTTP requests. If successfully exploited, this could cause a watchdog timer to expire and the device to reload, leading to a denial of service. It is important that organizations using the affected software implement necessary security measures as attackers require a valid user account to exploit this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco IOS XE Software 3.5.0E
Cisco IOS XE Software 3.5.1E
Cisco IOS XE Software 3.5.2E
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved