Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Cisco SD-WAN Path Traversal and Privilege Escalation (CVE-2022-20775)

Historical catalog analysis: CISA added this entry on February 25, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.

What the vulnerability is

CVE-2022-20775 is a path traversal vulnerability located within the application Command Line Interface (CLI) of Cisco SD-WAN. The flaw stems from improper access controls on specific commands, which could be leveraged by an authenticated local attacker to bypass intended restrictions. If successfully exploited, this vulnerability allows the attacker to execute arbitrary commands with root-level privileges.

Exposure and applicability

This vulnerability affects organizations deploying Cisco SD-WAN infrastructure where the application CLI is accessible. The attack vector is limited to authenticated local users; therefore, the primary exposure risk involves accounts that already possess valid credentials but lack administrative or root permissions.

Because this flaw allows for privilege escalation from a standard authenticated state to root access, it represents a significant risk to the integrity of the device’s operating environment and the confidentiality of the data passing through the SD-WAN fabric.

Remediation priorities

Based on the inclusion of this vulnerability in CISA’s Known Exploited Vulnerabilities catalog, remediation should be prioritized for all affected Cisco SD-WAN assets. Our analysis suggests the following priority sequence:

  1. Immediate Exposure Assessment: Identify all active Cisco SD-WAN deployments and determine if they are running versions susceptible to CVE-2022-20775.
  2. Application of Vendor Fixes: Deploy the security updates provided in the Cisco security advisory to address the underlying path traversal flaw.
  3. Hardening Implementation: Follow the specific “Hunt & Hardening Guidance” provided by CISA to reduce the attack surface of the CLI and mitigate the risk of local privilege escalation.
  4. Access Review: Audit authenticated users with CLI access to ensure the principle of least privilege is applied, reducing the number of potential local attackers who could attempt the exploit.

How to validate remediation

Verification must go beyond a simple version check, as software updates alone may not account for configuration-based exposures. To verify that exposure has been reduced, defenders should:

  • Cross-Reference Guidance: Confirm that both the vendor patch and the CISA hardening steps have been applied to each device.
  • Audit CLI Access: Verify that only authorized personnel possess the credentials required to access the application CLI.
  • Review Configuration State: Use the provided hunt guidance to check for indicators of compromise or misconfigurations that would allow path traversal, ensuring the environment matches the hardened state described in the advisory.

Limits and open questions

While patching addresses the vulnerability, residual risk remains if authenticated credentials have already been compromised. A patch prevents the exploit from working on a clean system but does not remove an attacker who has already achieved root access via this or other means.

Additionally, it remains unknown whether this vulnerability is being utilized by specific ransomware campaigns. Defenders should treat the lack of known ransomware association as a neutral data point rather than evidence of low risk, given its status as a known exploited vulnerability.

Source and editorial note

CVE-2022-20775: Cisco SD-WAN Path Traversal Vulnerability · Source date: February 25, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Archive date: February 28, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 19, 2026 at 00:48 UTC.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment