Executive brief
Cisco ThousandEyes Virtual Appliance is a network monitoring tool deployed on dedicated hardware. An authenticated attacker with admin credentials can inject malicious operating system commands through the web management interface by saving specially crafted configuration values, potentially executing arbitrary commands with root privileges and compromising the appliance.
Technical details
The vulnerability is a command injection flaw (CWE-78) in the web-based management interface caused by improper input validation on user-supplied configuration data. An authenticated attacker with valid administrative credentials can exploit this by submitting malicious configuration values through the web interface, which are then executed as operating system commands with root privileges. The attack vector is network-based and requires high privileges (admin credentials) but no additional user interaction. Cisco released fixed software in version 0.265.0 and later; there are no available workarounds.
Affected products
- Cisco ThousandEyes Virtual Appliance earlier than 0.265.0
Timeline
- 2026-09-16: disclosed