Cisco IOS XR Software Privilege Escalation Vulnerability in CLI

Vulnerability

A vulnerability exists in the Command Line Interface (CLI) of Cisco IOS XR Software, allowing an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of the affected device. This issue arises from inadequate validation of user arguments in specific CLI commands. An attacker with a low-privileged account could exploit this vulnerability by sending crafted commands at the prompt, potentially leading to unauthorized privilege escalation and execution of commands with root privileges.

Impact

Exploitation of this vulnerability could result in unauthorized privilege escalation, allowing an attacker to gain root access on the affected device's operating system and execute arbitrary commands.

Remediation

Cisco has released software updates to address this vulnerability. Customers should upgrade to version 25.2.21 or 25.4.2, depending on their current release. For platforms or releases not covered by these updates, contact Cisco support for a Maintenance Update (SMU).

Added: Mar 11, 2026, 5:30 PM
Updated: Mar 11, 2026, 5:30 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
3.5
remediation
8.3
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.