CVE-2025-20138 is a critical vulnerability in the CLI of Cisco IOS XR Software, allowing an authenticated, local attacker to execute arbitrary commands as root. This high-severity flaw (CVSS 8.8) stems from insufficient validation of user arguments, enabling a low-privileged attacker to craft commands and achieve root privilege escalation. While no public exploit code or active exploitation has been reported, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 24.2.21CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:x64:* | ||
>= 24.3, < 24.4CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.