CVE-2022-20775

HIGH KEV

Cisco SD-WAN Software - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-20775 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 25, 2026. EIP tracks 1 public exploit from researchers including bluefalconink.

AI-analyzed exploit summary This repository contains a detailed technical writeup and architecture documentation for a CISA ED 26-03 Compliance Tracker, focusing on remediation steps for CVE-2022-20775 and CVE-2026-20127. It includes code introspection scripts, architecture diagrams, and compliance tracking logic but does not contain functional exploit code.

Description

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF

Exploits (1)

nomisec WRITEUP
by bluefalconink · poc
https://github.com/bluefalconink/cisa-ed-26-03-tracker

This repository contains a detailed technical writeup and architecture documentation for a CISA ED 26-03 Compliance Tracker, focusing on remediation steps for CVE-2022-20775 and CVE-2026-20127. It includes code introspection scripts, architecture diagrams, and compliance tracking logic but does not contain functional exploit code.

Classification
Writeup 95%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Cisco SD-WAN (CVE-2022-20775, CVE-2026-20127)
No auth needed
Prerequisites: Access to the compliance tracker application · Understanding of CISA ED 26-03 requirements
devstral-2 · analyzed Feb 27, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.1247
EPSS Percentile 95.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2026-02-25
VulnCheck KEV 2026-02-25
ENISA EUVD EUVD-2022-26025
CWE
CWE-22 CWE-25
Status published
Products (10)
cisco/catalyst_sd-wan_manager 20.8
cisco/catalyst_sd-wan_manager 20.6 - 20.6.3
cisco/sd-wan 20.8
cisco/sd-wan 20.6 - 20.6.3
cisco/sd-wan_vbond_orchestrator 20.8
cisco/sd-wan_vbond_orchestrator 20.6 - 20.6.3
cisco/sd-wan_vedge_cloud 20.8
cisco/sd-wan_vedge_cloud < 20.6.3
cisco/sd-wan_vsmart_controller 20.8
cisco/sd-wan_vsmart_controller 20.6 - 20.6.3
Published Sep 30, 2022
KEV Added Feb 25, 2026
Tracked Since Feb 18, 2026