CVE-2026-20167

Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability

Severity
High 7.7
CVSS 3.1
Exploited
Not listed
EPSS
0.003
19.3th percentile
Discovered by
Third party
Published by the vendor
Published
May 6, 2026
Assigned by cisco

Description

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error handling. An attacker could exploit this vulnerability by submitting crafted input to the web-based management interface. A successful exploit could allow the attacker to request unauthorized files from a remote router, causing the router to reload and resulting in a DoS condition.

Weakness: CWE-284

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • Cisco · Cisco IoT Field Network Director (IoT-FND)