CVE-2021-1529High· 7.8▾ TwilightA vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the system CLI. An …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
Last analysed / modified upstream
0.3%
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges.
The vulnerability is due to insufficient input validation by the system CLI. An attacker could exploit this vulnerability by authenticating to an affected device and submitting crafted input to the system CLI. A successful exploit could allow the attacker to execute commands on the underlying operating system with root privileges.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Cisco IOS XE SD-WAN Software Command Injection Vulnerability. Released 2021-10-20, updated 2022-02-17.
Affected:
Cisco has released software updates that address this vulnerability. https://software.cisco.com
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-1278Medium· 5.5Cisco SD-WAN Denial of Service Vulnerabilties
CVE-2021-1274High· 7.5Cisco SD-WAN Denial of Service Vulnerabilties
CVE-2021-34727Critical· 9.8Cisco IOS XE SD-WAN Software Buffer Overflow Vulnerability (CVE-2021-34727)
CVE-2021-1612Medium· 5.5Cisco IOS XE SD-WAN Arbitrary File Overwrite Vulnerability
CVE-2026-20306Critical· 9.1A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root
CVE-2026-20305Critical· 9.1A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root