Buffer overflow in Cisco Systems, Inc products - CVE-2018-6242
Published: June 20, 2018 / Updated: January 4, 2026
Vulnerability details
The vulnerability allows a physical attacker to gain elevated privileges on the target system.
The vulnerability exists due to a buffer overflow vulnerability in NVIDIA TX1 BootROM when Recovery Mode (RCM) is active. A physical attacker can bypass secure boot and execute unverified code with elevated privileges.
Affected software
Cisco WebEx Room Kit
Cisco WebEx Room 70
Cisco WebEx Room 55
How to mitigate CVE-2018-6242
Cisco WebEx Room Kit - addressed in versions 9.2.6, 9.3.2
Cisco WebEx Room 70 - addressed in versions 9.2.6, 9.3.2
Cisco WebEx Room 55 - addressed in versions 9.2.6, 9.3.2
Links to Public Exploits and PoC-codes
- Exploit #12229 - NXLoader (An app that enables payload injection into a Switch console from an Android device by exploiting the CVE-2018-6242 vulnerability) (January 4, 2026)
- Exploit #4590 - fusee-gelee (Rust implementation of the Fusée Gelée exploit (CVE-2018-6242) for Tegra processors.) (September 11, 2020)
- Exploit #2149 - NXLoader (My first Android app: Launch Fusée Gelée payloads from stock Android (CVE-2018-6242)) (March 18, 2020)