Vulnerability intelligence
CVE-2026-20167
A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error handling. An attacker could exploit this vulnerability by submitting crafted input to the web-based management interface. A successful exploit could allow the attacker to request unauthorized files from a remote router, causing the router to reload and resulting in a DoS condition.
CVSS Score
7.7
High
EPSS — Exploit Probability
0.3%
Riskier than 19% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered May 7, 2026 · latest May 7, 2026
Coverage timeline
-
Cisco patches five high severity flaws across enterprise productswww.securityweek.com · May 7, 2026