Unauthorized Access in Cisco IOS Software HTTP Server Feature
CVE-2026-20125

7.7HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
25 March 2026

Badges

👾 Exploit Exists

What is CVE-2026-20125?

A vulnerability exists in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software that can allow an authenticated remote attacker to trigger a device reload. This issue arises from improper validation of user input, enabling an attacker to send malformed HTTP requests. If successfully exploited, this could cause a watchdog timer to expire and the device to reload, leading to a denial of service. It is important that organizations using the affected software implement necessary security measures as attackers require a valid user account to exploit this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Cisco IOS XE Software 3.5.0E

Cisco IOS XE Software 3.5.1E

Cisco IOS XE Software 3.5.2E

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.