---
id: CVE-2026-20167
title: "A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router.\r\n\r\nThis vulnerability is d…"
summary: "A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router.\r\n\r\nThis vulnerability is d…"
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'
cwe:
  - CWE-284
vendor: cisco
product: iot_field_network_director
affected:
  - iot_field_network_director < 5.0.0-117
patched:
  - iot_field_network_director 5.0.0-117
published: '2026-05-06'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20167'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iot-fnd-dos-n8N26Q4u
    label: psirt@cisco.com
tags:
  - nvd
epss: 0.00272
epssPercentile: 0.19874
ingestedAt: '2026-07-01T09:50:45.535Z'
---

## Overview

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router.

This vulnerability is due to improper error handling. An attacker could exploit this vulnerability by submitting crafted input to the web-based management interface. A successful exploit could allow the attacker to request unauthorized files from a remote router, causing the router to reload and resulting in a DoS condition.

## Affected

- `iot_field_network_director < 5.0.0-117`

## Remediation

Upgrade past the affected range:

- `iot_field_network_director 5.0.0-117`
