Executive brief
Cisco IoT Field Network Director, a platform used to manage large-scale industrial networks and smart grid infrastructure, contains a security flaw in its web management interface. An attacker with low-level user credentials could exploit this to access sensitive system files they are not authorized to see. This could lead to the exposure of configuration data or other internal information, potentially aiding further attacks on the network infrastructure.
Technical details
A path traversal vulnerability exists in the web-based management interface of Cisco IoT Field Network Director (IoT-FND). The root cause is insufficient file access checks when processing user-supplied input through the web interface. An authenticated, remote attacker with low privileges can exploit this by submitting crafted input to bypass directory restrictions. A successful exploit allows the attacker to read arbitrary files on the underlying filesystem that their account should not have permission to access. Cisco has addressed this in version 5.0.0-117; no workarounds are available.
Affected products
- Cisco IoT Field Network Director (IoT-FND) All versions prior to 5.0.0-117
Timeline
- 2026-05-06: advisory: Initial public release by Cisco
- 2026-05-06: disclosed