rootpwn

Vulnerabilities

Cisco Finesse Remote File Inclusion Vulnerability (CVE‑2026‑20175) – Unauthenticated Browser Exploit

Cisco Finesse now contains a remote file inclusion flaw that lets attackers inject arbitrary files into a user’s session via crafted HTTP requests. The weakness arises from insufficient input validation, allowing unauthenticated, remote attackers to load malicious scripts into the browser and steal data. Cisco has released patches; no workarounds are available, so affected systems must be updated immediately.

What the Flaw Does

Cisco Finesse can accept HTTP requests that reference external files. Because the input is not properly validated, an attacker can supply a URL pointing to a malicious script. When an end‑user clicks a crafted link, the script is loaded into the active session, executing in the victim’s browser context.

How Attackers Exploit It

An attacker who knows the device’s address can lure a user into clicking a link that contains that address and a reference to the malicious file. No authentication is required, and the payload runs with the privileges of the affected interface.

Impact

Successful exploitation can lead to:

  • Browser‑based attacks such as cross‑site scripting or session hijacking
  • Execution of arbitrary code on the device
  • Unauthorized access to sensitive information stored on the Finesse appliance

Mitigation

Cisco has issued software updates that fix the validation flaw. There are no interim workarounds. All affected installations should apply the latest patch as soon as possible.

CVE-2026-20175

Cisco Finesse RFI CVE-2026-20175 Browser Exploit Patch

← All news