← Back to overview

A critical vulnerability (CVE-2026-20212) has been identified in the Silicon One integration for Cisco Nexus 9000 Series Switches. The flaw allows an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerability stems from TCP ports 43210 and 43211 being accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). An attacker can connect to an affected device and send crafted input that executes as root-level code. Additionally, exploitation can cause the S1HAL process to crash, potentially forcing the device to reload. No authentication is required to exploit this vulnerability, making it particularly dangerous in exposed network environments. The issue is tracked under CVE-2026-20212 and has been published by both NVD and Cisco's Security Advisory portal.

Affected products

  • Cisco Nexus 9000 Series Switches

Related CVE's

  • CVE-2026-20212

IOC's

43210/tcp, 43211/tcp

Categories

  • Critical Infrastructure
  • Network Infrastructure
  • Zero-Day Vulnerabilities