rootpwn

Vulnerabilities

Cisco RoomOS USB Driver Flaw Lets Local Attacker Gain Root Privileges

A buffer‑overflow bug in Cisco’s RoomOS USB driver allows a physically‑present attacker to execute arbitrary code as root. The issue arises from missing boundary checks on USB data. Cisco has released patches; no workarounds are available.

A recent advisory reveals a critical flaw in Cisco RoomOS’s USB driver. The vulnerability stems from inadequate bounds checking on data received via the USB interface, which can be triggered by a malicious USB device. When exploited, the flaw causes a buffer overflow that grants an attacker full root privileges on the affected system.

Only an attacker with physical access to the device’s USB port can leverage this weakness. Cisco has issued software updates that address the issue, and there are currently no mitigations other than applying the patch.

Security teams should verify that all RoomOS deployments are updated to the latest firmware to eliminate the risk. The flaw is catalogued as CVE‑2026‑20302 with a medium severity rating.

Cisco RoomOS USB Privilege Escalation CVE-2026-20302 Patch

← All news