<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cisco — PoC Archive</title><link>https://poc.intelseclab.com/tags/cisco/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cisco/index.xml" rel="self" type="application/rss+xml"/><item><title>Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-20200-cisco-imc-argument-injection-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-20200-cisco-imc-argument-injection-rce/</guid><description>Critical severity (CVSS 9.9) — network · CVE-2026-20200 / NSIDE-SA-2026-003. Status: Patched. Affects: Cisco Integrated Management Controller (CIMC). Tags: cisco, imc, cimc, argument-injection, rce, redfish, curl, reverse-shell, arm, file-read, file-write, CVE-2026-20200.</description><category>network</category><category>Critical</category><category>cisco</category><category>imc</category><category>cimc</category><category>argument-injection</category><category>rce</category><category>redfish</category><category>curl</category><category>reverse-shell</category><category>arm</category><category>file-read</category><category>file-write</category><category>CVE-2026-20200</category></item><item><title>Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-19_cve-2026-20230-cisco-ucm-ssrf-arbitrary-file-write/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-19_cve-2026-20230-cisco-ucm-ssrf-arbitrary-file-write/</guid><description>Critical severity (CVSS 8.6) — network · CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW). Status: PoC — scanner/tester confirms the WebDialer precondition and SSRF reachability. Affects: Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) — WebDialer service. Tags: cisco, unified-communications-manager, ucm, webdialer, ssrf, cwe-918, unauthenticated, remote, privilege-escalation, kev, actively-exploited.</description><category>network</category><category>Critical</category><category>cisco</category><category>unified-communications-manager</category><category>ucm</category><category>webdialer</category><category>ssrf</category><category>cwe-918</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category><category>kev</category><category>actively-exploited</category></item><item><title>Cisco AsyncOS Spam Quarantine (TCP/6025) Exposure &amp; IOC Scanner (CVE-2025-20393)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-20393-cisco-asyncos-quarantine-rce-scanner/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-20393-cisco-asyncos-quarantine-rce-scanner/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-20393. Status: PoC. Affects: Cisco AsyncOS for Secure Email Gateway (ESA) / Security Management Appliance (SMA). Tags: cisco, asyncos, secure-email-gateway, sma, spam-quarantine, tcp-6025, unauthenticated-rce, exposure-scanner, ioc-detection, backdoor-detection, python.</description><category>network</category><category>Critical</category><category>cisco</category><category>asyncos</category><category>secure-email-gateway</category><category>sma</category><category>spam-quarantine</category><category>tcp-6025</category><category>unauthenticated-rce</category><category>exposure-scanner</category><category>ioc-detection</category><category>backdoor-detection</category><category>python</category></item><item><title>Cisco ASA/FTD WebVPN File-Handler Heap Buffer Overflow Exposure Scanner (CVE-2025-20333)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-20333-cisco-asa-ftd-webvpn-buffer-overflow/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-20333-cisco-asa-ftd-webvpn-buffer-overflow/</guid><description>Critical severity (CVSS 9.9) — network · CVE-2025-20333. Status: PoC. Affects: Cisco Secure ASA and Cisco Secure FTD (WebVPN / AnyConnect file upload handler). Tags: cisco, asa, ftd, webvpn, anyconnect, heap-buffer-overflow, cwe-120, rce-as-root, exposure-scanner, path-traversal, python.</description><category>network</category><category>Critical</category><category>cisco</category><category>asa</category><category>ftd</category><category>webvpn</category><category>anyconnect</category><category>heap-buffer-overflow</category><category>cwe-120</category><category>rce-as-root</category><category>exposure-scanner</category><category>path-traversal</category><category>python</category></item><item><title>Cisco Catalyst SD-WAN Peering Authentication Bypass — CVE-2026-20182</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-20182-cisco-sdwan-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-20182-cisco-sdwan-auth-bypass/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-20182. Status: Weaponized. Affects: Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage) — vdaemon control-connection process. Tags: cisco, sd-wan, vdaemon, dtls, authentication-bypass, netconf, vmanage, vsmart.</description><category>network</category><category>Critical</category><category>cisco</category><category>sd-wan</category><category>vdaemon</category><category>dtls</category><category>authentication-bypass</category><category>netconf</category><category>vmanage</category><category>vsmart</category></item><item><title>Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-20230-cisco-ucm-webdialer-ssrf-rce/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-20230-cisco-ucm-webdialer-ssrf-rce/</guid><description>Critical severity (CVSS 8.6) — network · CVE-2026-20230. Status: Weaponized. Affects: Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME). Tags: SSRF, RCE, Cisco, Unified-Communications-Manager, WebDialer, file-write, webshell, jsp-webshell, CISA-KEV, active-exploitation.</description><category>network</category><category>Critical</category><category>SSRF</category><category>RCE</category><category>Cisco</category><category>Unified-Communications-Manager</category><category>WebDialer</category><category>file-write</category><category>webshell</category><category>jsp-webshell</category><category>CISA-KEV</category><category>active-exploitation</category></item><item><title>Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-20262-cisco-sdwan-manager-file-write/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-20262-cisco-sdwan-manager-file-write/</guid><description>Medium severity (CVSS 6.5) — network · CVE-2026-20262. Status: PoC. Affects: Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). Tags: path-traversal, file-write, Cisco, SD-WAN, vManage, authenticated, CWE-22, active-exploitation.</description><category>network</category><category>Medium</category><category>path-traversal</category><category>file-write</category><category>Cisco</category><category>SD-WAN</category><category>vManage</category><category>authenticated</category><category>CWE-22</category><category>active-exploitation</category></item><item><title>Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-20245-cisco-sdwan-priv-esc/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-20245-cisco-sdwan-priv-esc/</guid><description>High severity (CVSS 7.8) — network · CVE-2026-20245. Status: PoC. Affects: Cisco Catalyst SD-WAN Manager (vManage), SD-WAN Controller (vSmart), SD-WAN Validator (vBond). Tags: privilege-escalation, Cisco, SD-WAN, vManage, file-upload, command-injection, root, CISA-KEV, no-patch, Mandiant, nation-state.</description><category>network</category><category>High</category><category>privilege-escalation</category><category>Cisco</category><category>SD-WAN</category><category>vManage</category><category>file-upload</category><category>command-injection</category><category>root</category><category>CISA-KEV</category><category>no-patch</category><category>Mandiant</category><category>nation-state</category></item></channel></rss>