Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-20302— Cisco RoomOS Stack Overflow Vulnerability

CVSS 6.1 · Medium EPSS 0.18% · P8

Affected Version Matrix 72

VendorProductVersion RangeStatus
CiscoCisco RoomOS SoftwareRoomOS 10.11.2.2affected
RoomOS 10.15.2.2affected
RoomOS 11.5.4.6affected
RoomOS 11.5.2.4affected
RoomOS 10.8.2.5affected
RoomOS 10.11.5.2affected
RoomOS 10.11.3.0affected
RoomOS 10.15.5.3affected
… +64 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-20302

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco RoomOS Stack Overflow Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges. This vulnerability is due to insufficient boundary checks for specific data that is provided through the USB driver. An attacker could exploit this vulnerability by connecting a malicious USB device to an affected device. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system and execute arbitrary code with root privileges.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Source: CVE Program / CVE List V5
Vulnerability Title
Cisco RoomOS Software 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco RoomOS Software是美国Cisco公司的一款视频会议软件。 Cisco RoomOS Software存在缓冲区错误漏洞,该漏洞源于USB驱动程序中特定数据的边界检查不足,可能导致未经身份验证的本地攻击者通过物理访问USB端口连接恶意USB设备,造成缓冲区溢出并以root权限执行任意代码。以下版本受到影响:RoomOS 10.11.2.2版本、RoomOS 10.15.2.2版本、RoomOS 11.5.4.6版本、RoomOS 11.5.2.4版本、RoomOS 10.8.2.5
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CiscoCisco RoomOS Software RoomOS 10.11.2.2 -

II. Public POCs for CVE-2026-20302

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-20302

登录查看更多情报信息。

Vendor Advisories for CVE-2026-20302 (1)

Same Patch Batch · Cisco · 2026-08-19 · 15 CVEs total

CVE-2026-2003010.0 CRITICALCisco Crosswork Security Hardening Release: August 2026
CVE-2026-2035810.0 CRITICALCisco Crosswork Security Hardening Release: August 2026
CVE-2026-2035710.0 CRITICALCisco Crosswork Security Hardening Release: August 2026
CVE-2026-2031710.0 CRITICALCisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentic
CVE-2026-2031510.0 CRITICALCisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Co
CVE-2026-202319.9 CRITICALCisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutraliz
CVE-2026-203599.9 CRITICALCisco Crosswork Security Hardening Release: August 2026
CVE-2026-203189.6 CRITICALCisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Val
CVE-2026-203197.5 HIGHCisco Secure Workload Software Security Hardening Release August 2026 - Buffer Management
CVE-2026-203207.5 HIGHCisco BroadWorks OCI解析器XEE漏洞
CVE-2026-203276.5 MEDIUMCisco Unified Intelligence Center SQL Injection Vulnerability
CVE-2026-202325.4 MEDIUMCisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability
CVE-2026-201775.3 MEDIUMCisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability
CVE-2026-203145.0 MEDIUMCisco Packaged Contact Center Enterprise & Cisco Unified Contact Center Enterprise Server-

IV. Related Vulnerabilities

V. Comments for CVE-2026-20302

No comments yet


Leave a comment