Cisco IOS XE Software Web-Based Management Interface Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the web-based management interface of Cisco IOS XE Software. This vulnerability allows authenticated, low-privileged, remote attackers to perform injection attacks on affected devices. The issue arises from inadequate input validation, enabling attackers to send crafted input that could be exploited to read limited files from the underlying operating system or to clear the syslog and licensing logs on the device.

Impact

Exploitation of this vulnerability could lead to unauthorized file access on the operating system or the ability to clear important system logs, potentially obscuring other malicious activities.

Remediation

Cisco has released software updates to address this vulnerability. Instructions for upgrading can be found on the Cisco Security Advisories page. Disabling the HTTP Server feature also eliminates the attack vector for this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
5.0
exploitability
4.9
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.