Executive brief
Cisco IoT Field Network Director is a management platform used to monitor and control large-scale industrial networks and routers. A security flaw in its web management interface allows a logged-in user with low-level permissions to manipulate files and run commands on the routers being managed by the system. This could lead to unauthorized data access, file deletion, or unauthorized configuration changes on critical network infrastructure.
Technical details
A command injection vulnerability (CWE-77) exists in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) due to insufficient input validation of user-supplied data. An authenticated, remote attacker with low privileges can exploit this by submitting specially crafted input through the web interface. Successful exploitation allows the attacker to create, read, or delete files and execute limited commands in user EXEC mode on managed remote routers. The vulnerability is tracked under Cisco Bug ID CSCwm80968 and has been addressed in IoT-FND release 5.0.0-117.
Affected products
- Cisco IoT Field Network Director (IoT-FND) 4.12.1 and earlier; 5.0.0-117 and earlier
Timeline
- 2026-05-06: advisory: Initial public release by Cisco
- 2026-05-06: disclosed