PT-2026-78494 · Cisco · Roomos

CVE-2026-20302

·

Published

2026-08-19

·

Updated

2026-08-20

CVSS v3.1

6.1

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco RoomOS (affected versions not specified)
Description An issue in the USB driver allows an unauthenticated local attacker with physical access to the USB port to execute arbitrary code with root privileges. This occurs due to insufficient boundary checks for data processed by the USB driver, which can lead to a buffer overflow condition—a situation where a program writes more data to a block of memory than it can hold—when a malicious USB device is connected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-20302

Affected Products

Roomos