Description
A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges.

This vulnerability is due to insufficient boundary checks for specific data that is provided through the USB driver. An attacker could exploit this vulnerability by connecting a malicious USB device to an affected device. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system and execute arbitrary code with root privileges.
Published: 2026-08-19
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack buffer overflow in the USB driver of Cisco RoomOS that can be triggered when a malicious USB device is connected. An attacker with physical access to the USB port can exploit the lack of boundary checks on driver data to execute arbitrary code as root, compromising the device’s confidentiality, integrity, and availability.

Affected Systems

Cisco RoomOS Software on devices that expose a USB port.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA KEV. Because the attack requires local physical access to a USB port, exploitation is limited to on‑premises or authorized personnel with physical proximity, but once accessed the attacker can gain full root privileges. Organizations should therefore consider this a significant local privilege escalation risk.

Generated by OpenCVE AI on August 20, 2026 at 14:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disconnect any unauthorized or unknown USB devices from Cisco RoomOS devices to eliminate immediate exploitation risk.
  • Apply available security updates or firmware releases from Cisco that address the USB driver boundary checking flaw.
  • Enable or enforce USB device whitelisting, allowing only trusted, signed devices to connect, and monitor port activity for anomalies.
  • Implement physical security controls to restrict unauthorized access to the device’s USB ports, such as lockable panels or lockable badges.

Generated by OpenCVE AI on August 20, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco cisco Roomos Software
Vendors & Products Cisco
Cisco cisco Roomos Software

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with&nbsp;root privileges. This vulnerability is due to insufficient boundary checks for specific data that is provided through the USB driver. An attacker could exploit this vulnerability by connecting a malicious USB device to an affected device. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system and execute arbitrary code with root privileges.
Title Cisco RoomOS Stack Overflow Vulnerability
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Cisco Cisco Roomos Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T15:57:08.625Z

Reserved: 2025-10-08T11:59:15.408Z

Link: CVE-2026-20302

cve-icon Vulnrichment

Updated: 2026-08-20T15:51:39.644Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T17:18:39.527

Modified: 2026-08-20T16:17:20.827

Link: CVE-2026-20302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T14:15:05Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')