CVE-2026-20167
Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability
Severity
High 7.7
CVSS 3.1
Exploited
Not listed
EPSS
0.003
19.3th percentile
Discovered by
Third party
Published by the vendor
Published
May 6, 2026
Assigned by cisco
Description
A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error handling. An attacker could exploit this vulnerability by submitting crafted input to the web-based management interface. A successful exploit could allow the attacker to request unauthorized files from a remote router, causing the router to reload and resulting in a DoS condition.
Weakness: CWE-284
Affected products
| Vendor | Product | Category | Matched by |
|---|
No product mapping yet — this CVE is pending taxonomy review.
Vendor-reported affected versions (1)
- Cisco · Cisco IoT Field Network Director (IoT-FND)