Junglewise Threat Intelligence

CVE-2026-20017: Cisco Secure FTD command injection in CLI

CVE-2026-20017 · Severity: medium · CVSS 6 · Published 2026-03-04

Technologies: Cisco Secure Firewall Threat Defense. Vendors: Cisco.

Executive brief

Cisco Secure Firewall Threat Defense (FTD) is a network security appliance that protects enterprise networks. Authenticated administrators or local users with valid credentials can exploit insufficient input validation in the CLI to execute arbitrary commands as root, potentially compromising the entire security appliance and the network it protects.

Technical details

This vulnerability is a command injection flaw in the CLI feature of Cisco Secure FTD Software, arising from insufficient input validation of user-supplied command arguments. An authenticated local attacker with valid administrative credentials can submit crafted input to a specific CLI command, allowing arbitrary command execution on the underlying operating system with root privileges. Attack vector is local (AV:L) and requires low-level privilege (PR:L). The impact scope is changed (S:C), affecting availability (A:H) of the system. Cisco has released software updates addressing this vulnerability; no workarounds are available.

Affected products

  • Cisco Secure Firewall Threat Defense

Timeline

  • 2026-03-04: disclosed: Cisco Security Advisory published

References

Related threats