Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

MonitorCVSS 4.3cisco-sa-webui-dos-qdc7qx3Aug 5, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A vulnerability in the Cisco IOS XE Software web-based management interface allows an authenticated remote attacker with low privileges to cause a denial of service. The vulnerability stems from insufficient input validation in the web management interface. By sending crafted input, an attacker can render the web-based management interface unresponsive, blocking remote GUI access to the device. Cisco has released software updates to address this issue. No workarounds are available.

What this means
What could happen
An authenticated attacker could crash the web management interface on a Cisco IOS XE device, temporarily preventing remote access and monitoring of the device through the GUI.
Who's at risk
Network administrators and plant operators managing Cisco IOS XE devices including Catalyst switches, Aironet access points, SD-WAN appliances, and ASR/ISR routers that use the web-based management interface for remote administration.
How it could be exploited
An attacker with valid low-privilege credentials logs into the web-based management interface and sends specially crafted input through a management function. The insufficient input validation causes the web server to become unresponsive, denying access to the interface.
Prerequisites
  • Valid login credentials (low-privilege account sufficient)
  • Network access to the web-based management interface (typically TCP 80 or 443)
  • Web UI enabled on the device
remotely exploitablerequires authentication (low-privilege)low complexityaffects network device management availability
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (6)
6 with fix
ProductAffected VersionsFix Status
Cisco IOS XE Software Web-Based Management Interface16.10.1 through 26.2.1eaFix available
Aironet Access Point Software (IOS XE Controller)All versionsFix available
IOS XE Catalyst SD-WANAll versionsFix available
IOS XE Software Bootloader (ROMMON)All versionsFix available
IOS XG SoftwareAll versionsFix available
IOS XR SoftwareAll versionsFix available
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDIf update cannot be applied immediately, restrict network access to the web management interface to trusted administrative networks only using firewall or ACL rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Cisco IOS XE Software to a patched version released by Cisco
Long-term hardening
0/2
HARDENINGDisable the web-based management interface if it is not actively used; manage the device via CLI or SSH instead
HARDENINGImplement strong authentication controls and regularly audit accounts with access to the management interface to reduce risk of credential compromise
API: /api/v1/advisories/b023bf84-e1e4-4cf9-9f20-35a2763f5025

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.