Junglewise Threat Intelligence

CVE-2026-20167: Cisco IoT Field Network Director DoS in managed routers

CVE-2026-20167 · Severity: high · CVSS 7.7 · Published 2026-05-06

Technologies: Cisco Iot Field Network Director. Vendors: Cisco.

Executive brief

Cisco IoT Field Network Director is a management platform used to monitor and control large-scale industrial networks and smart grid devices. A vulnerability in its web interface allows a logged-in user with low-level permissions to crash a connected router. This could lead to network outages and service disruptions in critical infrastructure environments.

Technical details

A vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) stems from improper error handling when processing user-supplied input. An authenticated, remote attacker with low privileges can exploit this by submitting crafted input to the interface. A successful exploit allows the attacker to request unauthorized files from a managed router, which triggers a reload of the router's operating system. This results in a Denial of Service (DoS) condition on the managed hardware. The vulnerability is tracked under Cisco Bug ID CSCwm81015 and has been addressed in version 5.0.0-117.

Affected products

  • Cisco IoT Field Network Director (IoT-FND) All versions prior to 5.0.0-117

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory
  • 2026-05-06: patched

References

Related threats