PoC Archive PoC Archive

tag

Cisco

  • CVE-2026-20200 / NSIDE-SA-2026-003 network CRITICAL 9.9

    Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)

    CVE-2026-20200 is an argument injection vulnerability in Cisco IMC that allows an authenticated user to achieve root-level RCE. The Redfish API SSH key upload handler (ManagerAccount.UploadSSHKey) passes the KeyURI parameter to curl without sanitization. An…

    Patched 2026-08-16
  • CVE-2026-20230 network CRITICAL 8.6 KEV EPSS 83%

    Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230)

    Cisco Unified Communications Manager's WebDialer service, when enabled, contains an improper-input-validation flaw that allows an unauthenticated remote attacker to conduct server-side request forgery (SSRF) attacks by sending crafted HTTP requests.…

    Patched 2026-07-19
  • CVE-2025-20393 network CRITICAL 10 KEV EPSS 30%

    Cisco AsyncOS Spam Quarantine (TCP/6025) Exposure & IOC Scanner (CVE-2025-20393)

    CVE-2025-20393 is an unauthenticated remote code execution vulnerability in Cisco AsyncOS's Spam Quarantine service, which listens on TCP/6025. This repository provides a detection-only tool that (1) checks whether TCP/6025 is reachable on a target Secure…

    Unverified 2026-07-06
  • CVE-2025-20333 network CRITICAL 9.9 KEV EPSS 40%

    Cisco ASA/FTD WebVPN File-Handler Heap Buffer Overflow Exposure Scanner (CVE-2025-20333)

    CVE-2025-20333 is a critical heap-based buffer overflow in the WebVPN file-upload handler of Cisco Secure ASA and FTD devices, which can lead to remote code execution as root when successfully exploited (typically after first bypassing authentication via the…

    Unverified 2026-07-06
  • CVE-2026-20182 network CRITICAL 10 KEV EPSS 90%

    Cisco Catalyst SD-WAN Peering Authentication Bypass — CVE-2026-20182

    Cisco Catalyst SD-WAN Controller and Manager rely on a peering authentication handshake between fabric control-plane devices over DTLS on UDP port 12346, handled by the vdaemon process. A flaw in how this control-connection handshake enforces peering…

    Patched 2026-07-05
  • CVE-2026-20230 network CRITICAL 8.6 KEV EPSS 83%

    Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230)

    CVE-2026-20230 is a critical server-side request forgery vulnerability in Cisco Unified CM / Unified CM SME caused by improper input validation of HTTP requests processed by the WebDialer component. A remote unauthenticated attacker can chain unauthenticated…

    Unverified 2026-07-01
  • CVE-2026-20262 network MEDIUM 6.5 KEV EPSS 28%

    Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262)

    CVE-2026-20262 is an authenticated remote arbitrary file write vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. Improper validation of user-supplied input during a file upload process enables path traversal, letting an authenticated attacker…

    Unverified 2026-07-01
  • CVE-2026-20245 network HIGH 7.8 KEV EPSS 25%

    Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245)

    CVE-2026-20245 is the seventh Cisco SD-WAN zero-day exploited in 2026. An authenticated attacker with netadmin privileges on Cisco Catalyst SD-WAN Manager can upload a specially crafted file to the CLI subsystem, triggering insufficient input validation and…

    Unpatched 2026-06-28