CVE-2025-20138

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 12, 2025
CWE ID 78

Summary

CVE-2025-20138 is a vulnerability affecting the CLI of Cisco IOS XR Software. This issue allows authenticated, local attackers to execute arbitrary commands as root on the underlying operating system of impacted devices. The vulnerability stems from insufficient validation of user arguments in certain CLI commands. A low-privileged attacker can exploit this weakness by inputting crafted commands at the prompt, potentially gaining root privileges and executing arbitrary commands.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share