Buffer Overflow in Cisco RoomOS USB Driver
CVE-2026-20302

6.1MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
19 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-20302?

A vulnerability in the USB driver of Cisco RoomOS enables an unauthenticated local attacker with physical access to exploit it by connecting a malicious USB device. This security flaw stems from insufficient boundary checks for specific data passed through the USB driver, which may lead to a buffer overflow condition on the system. Successful exploitation can result in the execution of arbitrary code with root privileges, posing a significant threat to the affected device. Ensure that your Cisco RoomOS is updated to mitigate this risk. Learn more in the Cisco advisory.

Affected Version(s)

Cisco RoomOS Software RoomOS 10.11.2.2

Cisco RoomOS Software RoomOS 10.15.2.2

Cisco RoomOS Software RoomOS 11.5.4.6

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.