PT-2025-39305 · Cisco · Cisco Ios Xe

Published

2025-09-24

·

Updated

2025-10-31

·

CVE-2025-20334

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software (affected versions not specified)
Description A flaw exists in the HTTP API subsystem of Cisco IOS XE Software that may allow a remote attacker to inject commands that will execute with root privileges on the underlying operating system. This is caused by inadequate input validation. An attacker with administrative privileges could exploit this by authenticating to an affected system and performing an API call with crafted input. An unauthenticated attacker could also persuade a legitimate user with administrative privileges to click a crafted link. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-11724
CVE-2025-20334

Affected Products

Cisco Ios Xe