Impact
The vulnerability stems from insufficient control flow management, classified as CWE‑691. This weakness allows an attacker to deviate program execution from its intended path, potentially leading to unauthorized actions or manipulation of the device’s operation. The impact is a compromise of integrity and trusted execution within Cisco Meraki firmware and software.
Affected Systems
Affected products include Cisco Campus Gateway Software, Cisco Meraki MR Wireless Access Points Software, Cisco Meraki MV Firmware, and Cisco Meraki MX Firmware. The advisory does not list specific firmware or software revision numbers beyond the October 2026 hardening release, so all versions of these products prior to that release are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits. Based on the description, the likely attack vector involves local or remote manipulation of the network device’s control flow, though the exact exploitation path is not detailed. The risk remains significant due to the high severity score and the potential for widespread impact on network infrastructure.
OpenCVE Enrichment