CVE-2025-20138 | Cisco IOS XR up to 24.4.10 CLI os command injection (cisco-sa-iosxr-priv-esc-GFQjxvOF / Nessus ID 274616)
A vulnerability labeled as critical has been found in Cisco IOS XR. This affects an unknown function of the component CLI. Such manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-20138. Local access is required to approach this attack. No exploit exists.
The affected component should be upgraded.