CVE-2025-20198 is a high-severity privilege escalation vulnerability in the Command Line Interface (CLI) of Cisco IOS XE Software. An authenticated local attacker with privilege level 15 can exploit insufficient input validation in specific configuration commands to elevate their privileges to root on the underlying operating system. This vulnerability has a CVSS score of 8.2 (High) due to its local attack vector, low attack complexity, and critical impact, allowing an attacker to gain full control over the device's operating system. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.7.0eCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.7.0e:*:*:*:*:*:*:* | ||
3.7.1eCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.7.1e:*:*:*:*:*:*:* | ||
3.7.2eCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.7.2e:*:*:*:*:*:*:* | ||
3.7.3eCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.7.3e:*:*:*:*:*:*:* | ||
3.7.4eCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.7.4e:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.