Executive brief
A vulnerability in Cisco IOS XR Software, used in high-end networking routers, could allow a user with low-level access to gain full administrative control of the device. By running a specific command that was incorrectly restricted, an attacker can bypass security checks to perform unauthorized actions. This could lead to a complete takeover of the router, potentially impacting network traffic and data security.
Technical details
A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software (specifically affecting IOS XRv 9000 Routers) could allow an authenticated, local attacker to elevate privileges. The root cause is an incorrect mapping of a specific command to task groups within the source code, which fails to enforce proper authorization checks. An attacker with low-privileged access can execute this specific command to bypass task group-based restrictions and gain full administrative control. Cisco has released software updates to address this issue, with version 25.2.2 being the first fixed release for the 25.2 branch. A workaround is available for environments using TACACS+ AAA command authorization to explicitly deny access to the affected command.
Affected products
- Cisco IOS XR Software All versions prior to 25.2.2
- Cisco IOS XRv 9000 Routers
Timeline
- 2026-03-11: advisory: Initial advisory published by Cisco
- 2026-03-11: patched: Fixed software releases made available