← Vulnerability feed

Vulnerability record · CVE-2026-20167 · published 6 May 2026

CVE-2026-20167: Cisco iot field network director improper access control vulnerability

Cisco · Iot Field Network Director

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error handling. An attacker could exploit this vulnerability by submitting crafted input to the web-based management interface. A successful exploit could allow the attacker to request unauthorized files from a remote router, causing the router to reload and resulting in a DoS condition.

7.7 CVSS 3.1 High EPSS 0.27% · top 82.4% CWE-284 · Improper access control
7.7CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
30 Jun 2026Last modified by NVD

Description

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error handling. An attacker could exploit this vulnerability by submitting crafted input to the web-based management interface. A successful exploit could allow the attacker to request unauthorized files from a remote router, causing the router to reload and resulting in a DoS condition.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-20167 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2020-3531Cisco iot field network director missing authentication for critical function vulnerabilityA vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end data…EPSS 2.2%8.8CVE-2020-26075Cisco iot field network director sql injection vulnerabilityA vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to gain access to the back-en…EPSS 1.6%8.8CVE-2018-0270Cisco iot field network director cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker t…EPSS 0.68%8.7CVE-2020-26072Cisco iot field network director improper access control vulnerabilityA vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify informat…EPSS 1.0%7.5CVE-2020-3392Cisco iot field network director missing authentication for critical function vulnerabilityA vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on…EPSS 1.5%7.5CVE-2020-26076Cisco iot field network director information exposure vulnerabilityA vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on a…EPSS 1.3%7.5CVE-2020-3162Cisco iot field network director improper input validation vulnerabilityA vulnerability in the Constrained Application Protocol (CoAP) implementation of Cisco IoT Field Network Director could allow an unauthenticated remo…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2026-20167), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.