logo

Public Flaws in Cisco IOx Allow Unauthenticated Log Injection and Admin XSS

ID: 49ebcb22-650b-5e6f-bc39-8ae58a0ddbec

STIX ID: report--49ebcb22-650b-5e6f-bc39-8ae58a0ddbec

Feed Name: securityonline.info

Threat Score
35/100

Date Published: 2026-03-26

Date Updated: 2026-04-23

Author: Ddos

...
...

Cisco published advisories for two Cisco IOx vulnerabilities in IOS XE: a stored XSS (CVE-2026-20112, CVSS 4.8) that requires valid administrative credentials to inject malicious script into the web management interface, and a CRLF injection (CVE-2026-20113, CVSS 5.3) that can be triggered by an unauthenticated attacker to tamper with log entries; both affect devices only when the Cisco IOx application hosting environment is manually configured (not enabled by default). Cisco reports no known malicious exploitation at publication time and advises applying official software updates since no workarounds exist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.