CVE-2026-20125Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malformed HTTP requests to an affected device. A successful exploit could allow the attacker to cause a watchdog timer to expire and the device to reload, resulting in a DoS condition. To exploit this vulnerability, the attacker must have a valid user account.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-228

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-30)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-26: 1Mentions · 2026-03-30: 2Technical Details · 2026-03-30: 103-2603-30
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-03-302
Disclosure2
Full discourse3 posts
  • EdgeDetectOps@EdgeDetectOps
    Disclosure

    CVE-2026-20125 hits Cisco IOS/IOS XE HTTP Server validation. This is infrastructure layer — the management interface that runs your network gear.

    Post summary

    A new vulnerability (CVE-2026-20125) affecting Cisco IOS/IOS XE HTTP Server validation has been disclosed, but no exploit, patch, or technical details are provided.

    1000034
    17 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20125 A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affect… https://www.cve.org/CVERecord?id=CVE-2026-20125 ----- Traducción: CVE-2026-20125 Una… http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑20125, a vulnerability in Cisco IOS software’s HTTP Server feature that allows an authenticated, remote attacker to cause an impact.

    0000032
    62 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20125 A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affect… https://www.cve.org/CVERecord?id=CVE-2026-20125

    Post summary

    The text provides a brief disclosure of CVE‑2026‑20125, noting it involves the HTTP Server feature in Cisco IOS/IOS XE and requires authentication for exploitation, but offers little further detail.

    00000183
    56.8K followersView on X

Explore more