Home Cisco CVE-2025-20334
Back to Cisco

CVE-2025-20334

Cisco IOS XE - HTTP API

Cisco CVSS 8.8 Updated March 16, 2026

Executive Risk Summary

"A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privileges into the underlying operating system. This vulnerability is due to insufficient input validation and can be exploited by an attacker with administrative privileges or by persuading a legitimate user to click a crafted link."

Operational Audit Arsenal

Target Type Firmware Image
Target Asset IOS XE Image
Standard Path Global Firmware

Manual Verification Required

This is a non-Windows asset (Cisco). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Network disruption possible during patch application

Internal Work Notes

CVE-2025-20334: Cisco IOS XE HTTP API vulnerability allowing remote command injection with root privileges. Verify version and apply patch according to Cisco Security Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xe-cmd-inject-rPJM8BGL

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Cisco Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.