CVE-2025-20138
Last modified
CVE-2025-20138 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the prompt. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the prompt. A successful exploit could allow the attacker to elevate privileges to root and execute arbitrary commands.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xr | < 24.2.21 |
| Cisco | Ios Xr | >= 24.3, < 24.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-20138?
How severe is CVE-2025-20138?
How do I fix CVE-2025-20138?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-20131A vulnerability in the GUI of Cisco Identity Services Engine…4.9
- CVE-2025-20133A vulnerability in the management and VPN web servers of the…8.6
- CVE-2025-20134A vulnerability in the certificate processing of Cisco Secur…8.6
- CVE-2025-20135A vulnerability in the DHCP client functionality of Cisco Se…4.3
- CVE-2025-20136A vulnerability in the function that performs IPv4 and IPv6 …8.6
- CVE-2025-20137A vulnerability in the access control list (ACL) programming…4.7
- CVE-2025-20139A vulnerability in chat messaging features of Cisco Enterpri…7.5
- CVE-2025-2014Ashlar-Vellum Cobalt VS File Parsing Use of Uninitialized Va…7.8
- CVE-2025-20140A vulnerability in the Wireless Network Control daemon (wncd…7.4
- CVE-2025-20141A vulnerability in the handling of specific packets that are…7.4
- CVE-2025-20142A vulnerability in the IPv4 access control list (ACL) featur…8.6
- CVE-2025-20143A vulnerability in the boot process of Cisco IOS XR Software…6.7
Are you affected by CVE-2025-20138?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
