What is CVE-2026-20302?
A vulnerability in the USB driver of Cisco RoomOS allows a local attacker with physical access to execute arbitrary code with root privileges due to insufficient boundary checks. Affected devices should have their USB ports physically secured or disabled to mitigate this threat.
Azərbaycanca: Cisco RoomOS əməliyyat sisteminin USB sürücüsündə aşkar edilmiş boşluq fiziki girişi olan lokal təcavüzkara xüsusi hazırlanmış data vasitəsilə root imtiyazları icra etməyə imkan verir. Xəbərdə qeyd olunur ki, zəiflik kifayət qədər "boundary check" olmamasından qaynaqlanır. Təsirlənmiş cihazlarda USB portlarına fiziki girişin məhdudlaşdırılması tövsiyə olunur.
Related CVEs
link basis: shared vendor: Cisco
FAQ2
What type of access does an attacker need to exploit CVE-2026-20302?
The attacker must have physical access to the device, as the vulnerability exists in the USB driver of Cisco RoomOS.
What is the root cause of CVE-2026-20302?
The vulnerability is caused by insufficient boundary checks in the USB driver.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.