Cisco RoomOS Software: remote code execution
Medium6.1CVE-2026-20302 · Published Aug 19, 2026 · updated Aug 20, 2026
A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges. This vulnerability is due to insufficient boundary checks for specific data that is provided through the USB driver. An attacker could exploit this vulnerability by connecting a malicious USB device to an affected device. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system and execute arbitrary code with root privileges.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cisco RoomOS Software Product | <= RoomOS 10.11.2.2 | No fix yet |
| <= RoomOS 10.15.2.2 | No fix yet | |
| <= RoomOS 11.5.4.6 | No fix yet | |
| <= RoomOS 11.5.2.4 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-120
More Cisco advisories
All Cisco| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 19 | Cisco Secure Workload: improper input validation | Critical9.6 | No fix yet |
| Aug 19 | Cisco Secure Workload: memory corruption | High7.5 | No fix yet |
| Aug 19 | Cisco BroadWorks: XML external entity | High7.5 | No fix yet |
| Aug 19 | Cisco Unified Intelligence Center: SQL injection | Medium6.5 | No fix yet |
| Aug 19 | Cisco Crosswork Planning: missing authentication | Critical10.0 | No fix yet |
| Aug 19 | As part of Cisco's ongoing commitment to proactive security and product quality | Critical10.0 | No fix yet |