Vulnerability record · CVE-2001-0537 · published 21 July 2001
CVE-2001-0537: Cisco IOS HTTP server authentication bypass via URL access level
Cisco · Ios
The HTTP server in Cisco IOS 11.3 through 12.2 fails to properly enforce local authorization, letting a remote attacker bypass authentication by specifying a high access level in the URL. Successful abuse grants full command execution on the device, making it a complete compromise of the router or switch.
Description
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote command execution on network infrastructure with complete impact and very high EPSS, despite the absence of KEV listing.
What it is
The HTTP server in Cisco IOS 11.3 through 12.2 fails to properly enforce local authorization, letting a remote attacker bypass authentication by specifying a high access level in the URL. Successful abuse grants full command execution on the device, making it a complete compromise of the router or switch.
Impact
An attacker gains full read and write control of the affected device, including the ability to run arbitrary IOS commands, alter configuration, and pivot into the network. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
Reachable over the network through the IOS HTTP server when local authorization is enabled; no credentials are required per the vector (Au:N), though the attack complexity is rated medium. No user interaction is described.
Exploitation
The record is not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.6845 (99.3rd percentile) and multiple references carry an Exploit tag, indicating public exploit material exists.
What to do
- Apply the Cisco patch referenced in the vendor advisory for the affected IOS release.
- Disable the IOS HTTP server (no ip http server) where it is not operationally required.
- Restrict management-plane access to trusted hosts with ACLs and out-of-band management.
- Replace local authorization with centralized AAA (TACACS+/RADIUS) if the HTTP server must remain enabled.
- Audit device configurations for exposed HTTP services and unexpected privilege levels.
Detection
- Monitor IOS HTTP server logs and syslog for requests containing unusual access-level parameters in the URL.
- Alert on configuration changes or privileged command execution originating from HTTP sessions.
- Baseline and review devices with the HTTP server enabled and local authorization in use.
- Watch for anomalous management-plane traffic to TCP/80 on IOS devices from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2001-0537 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-0537), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.