CVE-2001-0537

EXPLOITED NUCLEI

Cisco IOS 11.3-12.2 - Unauthenticated Command Execution via High Access Level URL

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2001-0537 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 6 public exploits from researchers including blackangels, Eliel C. Sardanons, cronos, including a Metasploit module auxiliary/scanner/http/cisco_ios_auth_bypass. A Nuclei detection template is also available.

AI-analyzed exploit summary This Perl script exploits multiple Cisco IOS vulnerabilities, including CVE-2001-0537, by sending crafted HTTP requests to gain unauthorized administrative access or cause denial of service. It targets Cisco routers and switches with various exploits, including authentication bypass and buffer overflows.

Description

HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

Exploits (6)

exploitdb WORKING POC VERIFIED
by blackangels · perlremotehardware
https://www.exploit-db.com/exploits/20978

This Perl script exploits multiple Cisco IOS vulnerabilities, including CVE-2001-0537, by sending crafted HTTP requests to gain unauthorized administrative access or cause denial of service. It targets Cisco routers and switches with various exploits, including authentication bypass and buffer overflows.

Classification
Working Poc 95%
Attack Type
Auth Bypass | Dos
Complexity
Moderate
Reliability
Reliable
Target: Cisco IOS (various versions)
No auth needed
Prerequisites: Network access to the target device · HTTP or Telnet service enabled on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Eliel C. Sardanons · cremotehardware
https://www.exploit-db.com/exploits/20976

This exploit leverages an authentication bypass vulnerability in Cisco IOS by sending crafted HTTP requests to the '/level/16/exec/' endpoint, allowing remote command execution with administrative privileges. The code establishes a socket connection to the target device and sends user-provided commands via HTTP GET requests.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Cisco IOS (affected versions)
No auth needed
Prerequisites: Network access to the target device · HTTP service enabled on the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb SCANNER VERIFIED
by cronos · perlremotehardware
https://www.exploit-db.com/exploits/20975

This Perl script checks for the Cisco IOS HTTP authentication bypass vulnerability (CVE-2001-0537) by iterating through privilege levels 16-99 and testing for unauthorized access. It sends HTTP requests to the target device and analyzes responses to determine vulnerability.

Classification
Scanner 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Cisco IOS (multiple versions)
No auth needed
Prerequisites: Network access to the target Cisco device · HTTP service enabled on the device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb SCANNER VERIFIED
by hypoclear · perlremotehardware
https://www.exploit-db.com/exploits/20977

This Perl script scans a range of IP addresses for the Cisco IOS HTTP Configuration Arbitrary Administrative Access Vulnerability (CVE-2001-0537). It attempts to exploit the vulnerability by sending HTTP requests to the target devices and checks for a successful response indicating administrative access.

Classification
Scanner 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Cisco IOS (affected versions)
No auth needed
Prerequisites: Network access to the target devices · HTTP service enabled on the target devices
devstral-2 · analyzed Feb 16, 2026 Full analysis →
vulncheck_xdb WORKING POC
remote
https://github.com/threat9/routersploit

This repository contains the RouterSploit framework, an exploitation toolkit for embedded devices. It includes modules for exploits, credential testing, scanners, and payloads, with a focus on router and IoT device vulnerabilities.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Embedded devices (routers, IoT, etc.)
No auth needed
Prerequisites: Python 3.6+ · Dependencies listed in requirements.txt
devstral-2 · analyzed Feb 25, 2026 Full analysis →
metasploit WORKING POC
by aushack, hdm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/cisco_ios_auth_bypass.rb

This Metasploit module exploits an authentication bypass vulnerability in Cisco IOS HTTP Server by sending a crafted GET request to access privileged configuration data. It iterates through privilege levels 16-99 to find a vulnerable endpoint and retrieves the device configuration.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Cisco IOS 11.3 to 12.2
No auth needed
Prerequisites: Network access to the Cisco IOS HTTP Server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Cisco IOS HTTP Configuration - Authentication Bypass
CRITICALVERIFIEDby DhiyaneshDK
Shodan: product:"Cisco IOS http config" && 200 || product:"cisco ios http config" || cpe:"cpe:2.3:o:cisco:ios"

References (10)

Core 10
Core References
Exploit, Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2001-14.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/4.3.2.7.2.20010629095801.0c3e6a70%40brussels.cisco.com
Exploit, Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/IOS-httplevel-pub.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/20010703011650.60515.qmail%40web14910.mail.yahoo.com
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/1601227034.20010702112207%40olympos.org
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/578
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/l-106.shtml
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2936
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6749

Scores

EPSS 0.9378
EPSS Percentile 99.9%

Details

VulnCheck KEV 2023-11-15
CWE
CWE-287
Status published
Products (50)
cisco/ios 11.3
cisco/ios 11.3aa
cisco/ios 11.3da
cisco/ios 11.3db
cisco/ios 11.3ha
cisco/ios 11.3ma
cisco/ios 11.3na
cisco/ios 11.3t
cisco/ios 11.3xa
cisco/ios 12.0
... and 40 more
Published Jul 21, 2001
Tracked Since Feb 18, 2026