CVE-2022-20775: Cisco SD-WAN
EPSS12.4%No. 1232 of 1739 in KEV
CVE year2022~4 yrs before listing
Same vendor in KEV100
Same product1
| Field | Value |
|---|---|
| Vendor | Cisco |
| Product | SD-WAN |
| Name | Cisco SD-WAN Path Traversal Vulnerability |
| Added to KEV | 2026-02-25 |
| US federal due date | 2026-02-27 |
| Ransomware use | Unknown |
| CWE | CWE-25, CWE-282 |
CISA description
Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Cisco SD-WAN vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-25.