CVE-2025-20138
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 12, 2025
CWE ID 78
Summary
CVE-2025-20138 is a vulnerability affecting the CLI of Cisco IOS XR Software. This issue allows authenticated, local attackers to execute arbitrary commands as root on the underlying operating system of impacted devices. The vulnerability stems from insufficient validation of user arguments in certain CLI commands. A low-privileged attacker can exploit this weakness by inputting crafted commands at the prompt, potentially gaining root privileges and executing arbitrary commands.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco IOS
Affected Vendors
- Cisco