Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2720 articles · 132349 vulns · 35/41 feeds (7d)
← Back to list
6.5
CVE-2026-20168
Cisco · Cisco IoT Field Network Director (IoT-FND)

Cisco IoT Field Network Director Path Traversal Vulnerability

Description

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficient file access checks. An attacker could exploit this vulnerability by submitting crafted input in the web-based management interface. A successful exploit could allow the attacker to read files that they are not authorized to access.

Affected Products

VendorProductVersions
CiscoCisco IoT Field Network Director (IoT-FND)4.5.1, 4.4.3, 4.1.0, 4.1.3, 4.6.1, 4.1.1, 4.4.0, 4.2.0, 4.4.2, 4.3.0, 4.6.0, 4.4.4, 4.3.2, 4.1.2, 4.4.1, 4.5.0, 4.3.1, 4.7.0, 4.6.2, 4.7.1, 4.7.2, 4.8.0, 4.8.1, 4.9.0, 4.9.1, 4.10.0, 4.9.2, 4.11.0, 4.12.0, 4.12.1

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iot-fnd-dos-n8N26Q4u

Related News (1 articles)

Tier C
VulDB8h ago
CVE-2026-20168 | Cisco IoT Field Network Director up to 4.12.1 Web-based Management Interface 7pk error (cisco-sa-iot-fnd-dos-n8N26Q4u)
→ No new info (linked only)
CVSS 3.16.5 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-388
PublishedMay 6, 2026
Last enriched8h ago
Trending Score23
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20188
Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Connection Exhaustion Denial of Service Vulnerability
Trending: 47
HIGHCVE-2026-20034
Cisco Unity Connection Remote Code Execution Vulnerability
Trending: 31
HIGHCVE-2026-20167
Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability
Trending: 26
HIGHCVE-2026-20185
Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vunerability
Trending: 26
HIGHCVE-2026-20035
Cisco Unity Connection Server-Side Request Forgery Vulnerability
Trending: 26

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 6, 2026
Discovered by ZDM
May 6, 2026