---
id: CVE-2026-20169
title: "A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router.\r\n\r\nThis vulnerability is…"
summary: "A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router.\r\n\r\nThis vulnerability is…"
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-77
vendor: cisco
product: iot_field_network_director
affected:
  - iot_field_network_director < 5.0.0-117
patched:
  - iot_field_network_director 5.0.0-117
published: '2026-05-06'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20169'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iot-fnd-dos-n8N26Q4u
    label: psirt@cisco.com
tags:
  - nvd
  - exploit-available
epss: 0.0021
epssPercentile: 0.11495
ingestedAt: '2026-06-29T21:48:47.453Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/gigachadusers/CVE-2026-20169'
  checkedAt: '2026-09-24T07:53:00.417Z'
exploitAvailable: true
---

## Overview

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router.

This vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by submitting crafted input in the web-based management interface. A successful exploit could allow the attacker to create, read, or delete files and execute limited commands in&nbsp;user EXEC mode on a remote router.

## Affected

- `iot_field_network_director < 5.0.0-117`

## Remediation

Upgrade past the affected range:

- `iot_field_network_director 5.0.0-117`
