Executive brief
A vulnerability in Cisco's firewall management software could allow a user with administrative access to bypass security restrictions and take full control of the underlying operating system. By entering specially crafted commands into the device's command-line interface, an attacker could gain root-level privileges, potentially leading to unauthorized data access or permanent modification of the security appliance. This issue affects specific Cisco Secure Firewall hardware, including the Firepower 2100, 4100, and 9300 series.
Technical details
This vulnerability (CVE-2026-20016) is classified as an argument injection flaw (CWE-88) within the Cisco FXOS Software CLI feature. The root cause is insufficient input validation of user-supplied command arguments for specific CLI commands. An attacker with valid administrative credentials can exploit this by submitting crafted input via a local terminal session. Successful exploitation allows the execution of arbitrary commands on the underlying Linux-based operating system with root privileges. The vulnerability specifically impacts Cisco Secure Firewall ASA and FTD software when running on Firepower 2100 (platform mode), 4100, and 9300 series appliances. Cisco has released software updates to address this issue; no workarounds are available.
Affected products
- Cisco Secure Firewall ASA Software 9.12.1 to 9.16.4.85, 9.17.1 to 9.18.4.66, 9.19.1 to 9.20.4, 9.22.1.1 to 9.22.2.4, 9.23.1 to 9.23.1.7
- Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0 to 7.0.9, 7.1.0 to 7.2.11, 7.3.0 to 7.4.3, 7.6.0 to 7.6.4, 7.7.0 to 7.7.11
- Cisco FXOS Software
Timeline
- 2026-03-04: advisory: Initial advisory published by Cisco
- 2026-03-04: disclosed
- 2026-03-04: patched