CVE-2025-20327: Cisco IOS

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation. An attacker could exploit this vulnerability by sending a crafted URL in an HTTP request. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Affected products

  • Cisco IOS: version 15.2(6)e2 only; version 15.2(6)e2a only; version 15.2(6)e2b only; version 15.2(6)e3 only; version 15.2(7)e only; version 15.2(7)e0a only; …

Published 2025-09-24. Last modified 2026-09-26.