Junglewise Threat Intelligence

CVE-2022-20775: Cisco SD-WAN privilege escalation via path traversal in CLI

CVE-2022-20775 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2026-02-25

Technologies: Cisco SD-WAN. Vendors: Cisco.

Executive brief

Cisco SD-WAN is a networking solution used to manage and secure wide-area networks across multiple locations. A vulnerability in its command-line interface could allow a user with basic access to bypass security restrictions and gain full administrative control of the device. This could lead to unauthorized configuration changes, data interception, or a complete shutdown of network services.

Technical details

A path traversal vulnerability (CWE-22/CWE-25) exists in the Command Line Interface (CLI) of Cisco SD-WAN Software. The flaw is caused by improper access controls and insufficient validation of input provided to specific CLI commands. An authenticated, local attacker can exploit this by executing a maliciously crafted command to traverse directories and access restricted system files. Successful exploitation allows the attacker to escalate privileges from a standard user to root, enabling arbitrary command execution with full system authority. Cisco has released software updates to address this issue; no workarounds are available.

Affected products

  • Cisco SD-WAN Software < 20.6.3, 20.7.x < 20.7.2, 20.8.x

Timeline

  • 2022-04-20: advisory: Original Cisco advisory published
  • 2026-02-25: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats