Junglewise Threat Intelligence

CVE-2026-20302: Cisco RoomOS buffer overflow in USB driver

CVE-2026-20302 · Severity: medium · CVSS 6.1 · Published 2026-08-19

Technologies: Cisco RoomOS. Vendors: Cisco.

Executive brief

Cisco RoomOS is a software platform used in video conferencing and collaboration devices. A flaw in its USB driver could allow an attacker with physical access to a USB port to run malicious code with the highest system privileges, potentially compromising the entire device and any communications or data passing through it.

Technical details

This is a buffer overflow vulnerability (CWE-120) in the USB driver of Cisco RoomOS caused by insufficient boundary checks on data passed through the USB interface. The vulnerability requires an attacker to have physical access to connect a malicious USB device; no authentication or network access is required. A successful exploit allows an unauthenticated local attacker to trigger a stack overflow and execute arbitrary code with root privileges. Cisco has released fixed software: RoomOS 11.32.7.0 or later for on-premises deployments, and 11.40.1.1 or later for cloud-aware deployments; version 26 users should upgrade to 26.7.2.2 or 26.7.1.12.

Affected products

  • Cisco RoomOS 11 and earlier, 26 before 26.7.2.2 (on-premises) or 26.7.1.12 (cloud-aware)

Timeline

  • 2026-08-19: disclosed

References

Related threats