Cisco bug lets hackers run commands as root on UWRB access points

Share:

Cisco has fixed a maximum severity vulnerability that allows attackers to run commands with root privileges on vulnerable Ultra-Reliable Wireless Backhaul (URWB) access points that provide connectivity for industrial wireless automation.

Tracked as CVE-2024-20418, this security flaw was found in Cisco’s Unified Industrial Wireless Software’s web-based management interface. Unauthenticated threat actors can exploit it in low-complexity command injection attacks that don’t require user interaction.

“This vulnerability is due to improper validation of input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected system,” Cisco said in a security advisory published on Wednesday.

“A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system of the affected device.”

As the company explains, the vulnerability impacts Catalyst IW9165D Heavy Duty Access Points, Catalyst IW9165E Rugged Access Points and Wireless Clients, and Catalyst IW9167E Heavy Duty Access Points, but only if they’re running vulnerable software and have the URWB operating mode enabled.

Cisco’s Product Security Incident Response Team (PSIRT) has yet to discover evidence of publicly available exploit code or that this critical security flaw has been exploited in attacks.

Admins can determine if the URWB operating mode is enabled by checking if the “show mpls-config” CLI command is available. If the command is not available, URWB is disabled, and the device will not be affected by this vulnerability.

Cisco also fixed a denial-of-service flaw in its Cisco ASA and Firepower Threat Defense (FTD) software in July, which was discovered in April while exploited in large-scale brute-force attacks targeting Cisco VPN devices.

One month earlier, the company released security updates to address another command injection vulnerability with public exploit code that lets attackers escalate privileges to root on vulnerable systems.

​In July, CISA and the FBI urged software companies to eliminate path OS command injection vulnerabilities before shipping in response to recent attacks where Cisco, Palo Alto, and Ivanti network edge devices were compromised by exploiting multiple OS command injection security flaws (CVE-2024-20399, CVE-2024-3400, and CVE-2024-21887).

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:59 am, Jun 29, 2025
weather icon 20°C
L: 19° | H: 21°
clear sky
Humidity: 81 %
Pressure: 1025 mb
Wind: 7 mph WNW
Wind Gust: 12 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:46 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
19° | 21°°C 0 mm 0% 6 mph 82 % 1026 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
20° | 34°°C 1 mm 100% 6 mph 66 % 1022 mb 0 mm/h
Tue Jul 01 10:00 pm
weather icon
20° | 32°°C 0.77 mm 77% 11 mph 68 % 1019 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
16° | 24°°C 1 mm 100% 12 mph 89 % 1019 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
15° | 22°°C 0 mm 0% 15 mph 81 % 1022 mb 0 mm/h
Today 4:00 am
weather icon
18° | 20°°C 0 mm 0% 5 mph 82 % 1024 mb 0 mm/h
Today 7:00 am
weather icon
19° | 19°°C 0 mm 0% 5 mph 81 % 1025 mb 0 mm/h
Today 10:00 am
weather icon
23° | 23°°C 0 mm 0% 4 mph 58 % 1026 mb 0 mm/h
Today 1:00 pm
weather icon
28° | 28°°C 0 mm 0% 5 mph 43 % 1025 mb 0 mm/h
Today 4:00 pm
weather icon
30° | 30°°C 0 mm 0% 3 mph 35 % 1023 mb 0 mm/h
Today 7:00 pm
weather icon
30° | 30°°C 0 mm 0% 1 mph 34 % 1021 mb 0 mm/h
Today 10:00 pm
weather icon
24° | 24°°C 0 mm 0% 6 mph 56 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
22° | 22°°C 0 mm 0% 6 mph 64 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,722.41
0.33%
Ethereum(ETH)
€2,082.66
0.82%
Tether(USDT)
€0.85
-0.01%
XRP(XRP)
€1.86
1.62%
Solana(SOL)
€128.65
6.07%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.140045
1.78%
Shiba Inu(SHIB)
€0.000010
1.98%
Pepe(PEPE)
€0.000009
3.98%
Scroll to Top