Path Manipulation Vulnerability in ExtremeXOS Utilities
CVE-2026-8170
What is CVE-2026-8170?
The mv, cp, and rm utilities in the ExtremeXOS shell environment contain a vulnerability that fails to safely canonicalize paths, allowing attackers with low-privilege command-line interface access to create symbolic links pointing to privileged file locations. This misbehavior can enable these attackers to read, alter, or replace critical files, potentially leading to escalated privileges all the way to root access. The vulnerability can be exploited both remotely by users holding low-privilege accounts and locally via the serial console, representing a substantial security risk that may allow persistent changes to the device software stack.
Affected Version(s)
Switch Engine (EXOS) Switch Engine 0 < 31.7.4
Switch Engine (EXOS) Switch Engine 32.0.0 < 32.7.4.15
Switch Engine (EXOS) Switch Engine 33.0.0 < 33.1.100
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
