CVE-2026-20113
EUVD-2026-1544325.03.2026, 16:16
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to arbitrarily inject log entries, manipulate the structure of log files, or obscure legitimate log events.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cisco | ios_xe | 16.6.1 |
| cisco | ios_xe | 16.6.2 |
| cisco | ios_xe | 16.6.3 |
| cisco | ios_xe | 16.6.4 |
| cisco | ios_xe | 16.6.5 |
| cisco | ios_xe | 16.6.4a |
| cisco | ios_xe | 16.6.5a |
| cisco | ios_xe | 16.6.6 |
| cisco | ios_xe | 16.6.7 |
| cisco | ios_xe | 16.6.8 |
| cisco | ios_xe | 16.6.9 |
| cisco | ios_xe | 16.6.10 |
| cisco | ios_xe | 16.7.1 |
| cisco | ios_xe | 16.7.1a |
| cisco | ios_xe | 16.7.1b |
| cisco | ios_xe | 16.7.2 |
| cisco | ios_xe | 16.7.3 |
| cisco | ios_xe | 16.7.4 |
| cisco | ios_xe | 16.8.1 |
| cisco | ios_xe | 16.8.1a |
| cisco | ios_xe | 16.8.1b |
| cisco | ios_xe | 16.8.1s |
| cisco | ios_xe | 16.8.1c |
| cisco | ios_xe | 16.8.1d |
| cisco | ios_xe | 16.8.2 |
| cisco | ios_xe | 16.8.1e |
| cisco | ios_xe | 16.8.3 |
| cisco | ios_xe | 16.9.1 |
| cisco | ios_xe | 16.9.2 |
| cisco | ios_xe | 16.9.1a |
| cisco | ios_xe | 16.9.1b |
| cisco | ios_xe | 16.9.1s |
| cisco | ios_xe | 16.9.3 |
| cisco | ios_xe | 16.9.4 |
| cisco | ios_xe | 16.9.5 |
| cisco | ios_xe | 16.9.5f |
| cisco | ios_xe | 16.9.6 |
| cisco | ios_xe | 16.9.7 |
| cisco | ios_xe | 16.9.8 |
| cisco | ios_xe | 16.10.1 |
| cisco | ios_xe | 16.10.1a |
| cisco | ios_xe | 16.10.1b |
| cisco | ios_xe | 16.10.1s |
| cisco | ios_xe | 16.10.1c |
| cisco | ios_xe | 16.10.1e |
| cisco | ios_xe | 16.10.1d |
| cisco | ios_xe | 16.10.2 |
| cisco | ios_xe | 16.10.1f |
| cisco | ios_xe | 16.10.1g |
| cisco | ios_xe | 16.10.3 |
| cisco | ios_xe | 16.11.1 |
| cisco | ios_xe | 16.11.1a |
| cisco | ios_xe | 16.11.1b |
| cisco | ios_xe | 16.11.2 |
| cisco | ios_xe | 16.11.1s |
| cisco | ios_xe | 16.12.1 |
| cisco | ios_xe | 16.12.1s |
| cisco | ios_xe | 16.12.1a |
| cisco | ios_xe | 16.12.1c |
| cisco | ios_xe | 16.12.1w |
| cisco | ios_xe | 16.12.2 |
| cisco | ios_xe | 16.12.1y |
| cisco | ios_xe | 16.12.2a |
| cisco | ios_xe | 16.12.3 |
| cisco | ios_xe | 16.12.8 |
| cisco | ios_xe | 16.12.2s |
| cisco | ios_xe | 16.12.1x |
| cisco | ios_xe | 16.12.1t |
| cisco | ios_xe | 16.12.4 |
| cisco | ios_xe | 16.12.3s |
| cisco | ios_xe | 16.12.3a |
| cisco | ios_xe | 16.12.4a |
| cisco | ios_xe | 16.12.5 |
| cisco | ios_xe | 16.12.6 |
| cisco | ios_xe | 16.12.1z1 |
| cisco | ios_xe | 16.12.5a |
| cisco | ios_xe | 16.12.5b |
| cisco | ios_xe | 16.12.1z2 |
| cisco | ios_xe | 16.12.6a |
| cisco | ios_xe | 16.12.7 |
| cisco | ios_xe | 16.12.10a |
| cisco | ios_xe | 16.12.11 |
| cisco | ios_xe | 17.1.1 |
| cisco | ios_xe | 17.1.1a |
| cisco | ios_xe | 17.1.1s |
| cisco | ios_xe | 17.1.1t |
| cisco | ios_xe | 17.1.3 |
| cisco | ios_xe | 17.2.1 |
| cisco | ios_xe | 17.2.1r |
| cisco | ios_xe | 17.2.1a |
| cisco | ios_xe | 17.2.1v |
| cisco | ios_xe | 17.2.2 |
| cisco | ios_xe | 17.2.3 |
| cisco | ios_xe | 17.3.1 |
| cisco | ios_xe | 17.3.2 |
| cisco | ios_xe | 17.3.3 |
| cisco | ios_xe | 17.3.1a |
| cisco | ios_xe | 17.3.1w |
| cisco | ios_xe | 17.3.2a |
| cisco | ios_xe | 17.3.1x |
| cisco | ios_xe | 17.3.1z |
| cisco | ios_xe | 17.3.4 |
| cisco | ios_xe | 17.3.5 |
| cisco | ios_xe | 17.3.4a |
| cisco | ios_xe | 17.3.6 |
| cisco | ios_xe | 17.3.4b |
| cisco | ios_xe | 17.3.4c |
| cisco | ios_xe | 17.3.5a |
| cisco | ios_xe | 17.3.5b |
| cisco | ios_xe | 17.3.7 |
| cisco | ios_xe | 17.3.8 |
| cisco | ios_xe | 17.3.8a |
| cisco | ios_xe | 17.4.1 |
| cisco | ios_xe | 17.4.2 |
| cisco | ios_xe | 17.4.1a |
| cisco | ios_xe | 17.4.1b |
| cisco | ios_xe | 17.4.2a |
| cisco | ios_xe | 17.5.1 |
| cisco | ios_xe | 17.5.1a |
| cisco | ios_xe | 17.6.1 |
| cisco | ios_xe | 17.6.2 |
| cisco | ios_xe | 17.6.1w |
| cisco | ios_xe | 17.6.1a |
| cisco | ios_xe | 17.6.1x |
| cisco | ios_xe | 17.6.3 |
| cisco | ios_xe | 17.6.1y |
| cisco | ios_xe | 17.6.1z |
| cisco | ios_xe | 17.6.3a |
| cisco | ios_xe | 17.6.4 |
| cisco | ios_xe | 17.6.1z1 |
| cisco | ios_xe | 17.6.5 |
| cisco | ios_xe | 17.6.6 |
| cisco | ios_xe | 17.6.6a |
| cisco | ios_xe | 17.6.5a |
| cisco | ios_xe | 17.6.7 |
| cisco | ios_xe | 17.6.8 |
| cisco | ios_xe | 17.6.8a |
| cisco | ios_xe | 17.7.1 |
| cisco | ios_xe | 17.7.1a |
| cisco | ios_xe | 17.7.1b |
| cisco | ios_xe | 17.7.2 |
| cisco | ios_xe | 17.10.1 |
| cisco | ios_xe | 17.10.1a |
| cisco | ios_xe | 17.10.1b |
| cisco | ios_xe | 17.8.1 |
| cisco | ios_xe | 17.8.1a |
| cisco | ios_xe | 17.9.1 |
| cisco | ios_xe | 17.9.1w |
| cisco | ios_xe | 17.9.2 |
| cisco | ios_xe | 17.9.1a |
| cisco | ios_xe | 17.9.1x |
| cisco | ios_xe | 17.9.1y |
| cisco | ios_xe | 17.9.3 |
| cisco | ios_xe | 17.9.2a |
| cisco | ios_xe | 17.9.1x1 |
| cisco | ios_xe | 17.9.3a |
| cisco | ios_xe | 17.9.4 |
| cisco | ios_xe | 17.9.1y1 |
| cisco | ios_xe | 17.9.5 |
| cisco | ios_xe | 17.9.4a |
| cisco | ios_xe | 17.9.5a |
| cisco | ios_xe | 17.9.5b |
| cisco | ios_xe | 17.9.6 |
| cisco | ios_xe | 17.9.6a |
| cisco | ios_xe | 17.9.7 |
| cisco | ios_xe | 17.9.5e |
| cisco | ios_xe | 17.9.5f |
| cisco | ios_xe | 17.9.8 |
| cisco | ios_xe | 17.9.7a |
| cisco | ios_xe | 17.9.7b |
| cisco | ios_xe | 17.11.1 |
| cisco | ios_xe | 17.11.1a |
| cisco | ios_xe | 17.12.1 |
| cisco | ios_xe | 17.12.1w |
| cisco | ios_xe | 17.12.1a |
| cisco | ios_xe | 17.12.1x |
| cisco | ios_xe | 17.12.2 |
| cisco | ios_xe | 17.12.3 |
| cisco | ios_xe | 17.12.2a |
| cisco | ios_xe | 17.12.1y |
| cisco | ios_xe | 17.12.1z |
| cisco | ios_xe | 17.12.4 |
| cisco | ios_xe | 17.12.3a |
| cisco | ios_xe | 17.12.1z1 |
| cisco | ios_xe | 17.12.1z2 |
| cisco | ios_xe | 17.12.4a |
| cisco | ios_xe | 17.12.5 |
| cisco | ios_xe | 17.12.4b |
| cisco | ios_xe | 17.12.1z3 |
| cisco | ios_xe | 17.12.5a |
| cisco | ios_xe | 17.12.1z4 |
| cisco | ios_xe | 17.12.6 |
| cisco | ios_xe | 17.12.5b |
| cisco | ios_xe | 17.12.5c |
| cisco | ios_xe | 17.12.6a |
| cisco | ios_xe | 17.12.5d |
| cisco | ios_xe | 17.12.1z5 |
| cisco | ios_xe | 17.12.1z6 |
| cisco | ios_xe | 17.12.6b |
| cisco | ios_xe | 17.13.1 |
| cisco | ios_xe | 17.13.1a |
| cisco | ios_xe | 17.14.1 |
| cisco | ios_xe | 17.14.1a |
| cisco | ios_xe | 17.15.1 |
| cisco | ios_xe | 17.15.1w |
| cisco | ios_xe | 17.15.1a |
| cisco | ios_xe | 17.15.2 |
| cisco | ios_xe | 17.15.1b |
| cisco | ios_xe | 17.15.1x |
| cisco | ios_xe | 17.15.1z |
| cisco | ios_xe | 17.15.3 |
| cisco | ios_xe | 17.15.2c |
| cisco | ios_xe | 17.15.2a |
| cisco | ios_xe | 17.15.1y |
| cisco | ios_xe | 17.15.2b |
| cisco | ios_xe | 17.15.3a |
| cisco | ios_xe | 17.15.4 |
| cisco | ios_xe | 17.15.3b |
| cisco | ios_xe | 17.15.4d |
| cisco | ios_xe | 17.15.4e |
| cisco | ios_xe | 17.16.1 |
| cisco | ios_xe | 17.16.1a |
| cisco | ios_xe | 17.17.1 |
| cisco | ios_xe | 17.18.1 |
| cisco | ios_xe | 17.18.1w |
| cisco | ios_xe | 17.18.1a |
| cisco | ios_xe | 17.18.1x |
𝑥
= Vulnerable software versions