Cisco IOS XE Software CLI Argu... Note

Cisco IOS XE Software CLI Argument Injection Vulnerability

A vulnerability exists in the command-line interface (CLI) of Cisco IOS XE Software. This flaw allows an authenticated local attacker with administrative privileges to run arbitrary commands as root. The vulnerability stems from inadequate validation of user arguments provided to certain CLI commands. To exploit this, an attacker needs to log in to the device's CLI using valid administrative credentials. They would then use specially crafted commands at the prompt. A successful attack grants the attacker the ability to execute any command with root privileges on the device's operating system. Cisco has released software updates to fix this vulnerability. Currently, there are no temporary solutions or workarounds available. This issue is tracked as CVE-2025-20338. The security impact rating for this vulnerability is considered medium.