CVE-2026-20169
EUVD-2026-2785406.05.2026, 17:16
A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by submitting crafted input in the web-based management interface. A successful exploit could allow the attacker to create, read, or delete files and execute limited commands in user EXEC mode on a remote router.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cisco | iot_field_network_director | 𝑥 < 5.0.0-117 |
𝑥
= Vulnerable software versions