logo

Max-Critical Cisco Bug Enables Command-Injection Attacks

ID: 2cdb731e-e298-54f8-be41-318c6ca85c37

STIX ID: report--2cdb731e-e298-54f8-be41-318c6ca85c37

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-11-07

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Cisco has disclosed a critical (CVSS 10) command-injection vulnerability (CVE-2024-20418) in its Unified industrial Wireless Software for Ultra-Reliable Wireless Backhaul (URWB) access points that allows unauthenticated HTTP requests to the device web management interface to execute arbitrary commands as root; the flaw affects Catalyst IW9165D, IW9165E, and IW9167E when URWB mode is enabled, Cisco provided a patch and reports no known public exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.