The researchers found a critical vulnerability in the popular tac_plus server, which serves the TACACS+ protocol and centrally checks administrators’ access to routers, switches, and other network hardware. The error allows you to achieve remote code execution before checking the login and password, and tac_plus in the standard configuration is started with root rights. The correction has already been released, but Facebook's archive fork remains vulnerable.
The problem is not in the TACACS+ protocol itself, but in the old tac_plus server code, which goes back to the open Developer's Kit Cisco in the mid-1990s. TACACS+ operates on top of TCP, usually on port 49, and combines three AAA functions. The server confirms the identity of the administrator, determines the permitted actions and records the executed commands. Compromising such a node is particularly dangerous, since a large number of network devices can be controlled through it.
The error refers to the vulnerability class of the format string. tac_plus places the field received from the client port in the error message, then transmits the collected line of the logging function as a control format, and not as ordinary data. Special sequences inside the inputs can cause the process to read or change memory and eventually execute foreign code.
Two TACACS+ packages are sufficient to get into a vulnerable area. The first correct request AUTHEN/START saves the controlled data, the second deliberately damaged package translates the server into an erroneous processing path. The username and password have not yet been checked.
However, the researchers do not claim that any access to TCP/49 automatically results in hacking. If a long random general secret is configured between the client and the server, the attacker needs to get or pick it up. Elttam estimated the severity of the vulnerability in 9.8 CVSS scores in the absence of an effective secret or with a weak key and 8.1 points with a long random key. Such estimates belong to researchers and are not yet the official assessment of CVE.
The weak cryptographic defense of the old TACACS+ is noticeably worsening the situation. The researchers showed that the server is able to return to authentication a predictable message converted with a common secret. Having received one such response, the attacker can check the weak key options locally without sending each password to the server. The TACACS+ defense mechanism itself has long been considered insufficient and in December 2025, the IETF identified TLS 1.3 as modern transport for the protocol, abandoning the old obfuscation scheme.
Elttam has verified another scenario in which malicious data is transmitted to the TACACS+ server through a trusted network device. The researchers were able to replicate behavior in a lab with an overly long username, but did not check the chain on the serial equipment of different manufacturers. Therefore, the ability to attack the server through an Internet-accessible login form depends on the specific implementation of the TACACS + client and should not yet be considered a universal method of operation.
Vulnerable code is present in the versions of Shrubbery Networks tac_plus up to F4.0.4.31 inclusive. On September 21, the developers released F4.0.4.32, where they fixed both found errors of the format line. The Facebook F4.0.4.28-7fb fork also contains a major vulnerable site, however, its repository was archived in August 2025 and no updates are expected for it. Elttam also warns of unknown number of assembly derivatives and embedded versions based on Cisco’s old code.
Cisco PSIRT told researchers that modern Cisco products do not use vulnerable versions of code and are not affected by the problem. CVE is not yet assigned at the time of publication. There is also no public evidence of exploitation of a new vulnerability in real attacks.
The interest of intruders in the TACACS+ infrastructure has long gone beyond the theory. China-linked Salt Typhoon operators intercepted TACACS+ traffic on compromised routers, extracted common secrets from configurations, and changed AAA parameters to move further across networks. Those attacks did not exploit the new tac_plus vulnerability, but show the value of centralized authentication systems for cyber espionage.
In August 2026, researchers also described the Fire Ant campaign, whose participants had already infiltrated directly into the tac_plus processes. The malware TacTap set introduced the library into the server, intercepted authentication sessions, and collected administrator credentials. The links between Fire Ant, Salt Typhoon and the new tac_plus error were not established.
Shrubbery tac_plus administrators are advised to upgrade to F4.0.4.32. For the archive fork of Facebook and other derivatives of the assemblies, you will need to independently correct or switch to a supported implementation. Prior to the update, the researchers advise allowing access to TCP/49 only trusted network hardware addresses and using a long random unique common secret. In the long run, it is safer to switch to TACACS+ on top of TLS 1.3, as the old traffic protection mechanism no longer meets modern security requirements.
The problem is not in the TACACS+ protocol itself, but in the old tac_plus server code, which goes back to the open Developer's Kit Cisco in the mid-1990s. TACACS+ operates on top of TCP, usually on port 49, and combines three AAA functions. The server confirms the identity of the administrator, determines the permitted actions and records the executed commands. Compromising such a node is particularly dangerous, since a large number of network devices can be controlled through it.
The error refers to the vulnerability class of the format string. tac_plus places the field received from the client port in the error message, then transmits the collected line of the logging function as a control format, and not as ordinary data. Special sequences inside the inputs can cause the process to read or change memory and eventually execute foreign code.
Two TACACS+ packages are sufficient to get into a vulnerable area. The first correct request AUTHEN/START saves the controlled data, the second deliberately damaged package translates the server into an erroneous processing path. The username and password have not yet been checked.
However, the researchers do not claim that any access to TCP/49 automatically results in hacking. If a long random general secret is configured between the client and the server, the attacker needs to get or pick it up. Elttam estimated the severity of the vulnerability in 9.8 CVSS scores in the absence of an effective secret or with a weak key and 8.1 points with a long random key. Such estimates belong to researchers and are not yet the official assessment of CVE.
The weak cryptographic defense of the old TACACS+ is noticeably worsening the situation. The researchers showed that the server is able to return to authentication a predictable message converted with a common secret. Having received one such response, the attacker can check the weak key options locally without sending each password to the server. The TACACS+ defense mechanism itself has long been considered insufficient and in December 2025, the IETF identified TLS 1.3 as modern transport for the protocol, abandoning the old obfuscation scheme.
Elttam has verified another scenario in which malicious data is transmitted to the TACACS+ server through a trusted network device. The researchers were able to replicate behavior in a lab with an overly long username, but did not check the chain on the serial equipment of different manufacturers. Therefore, the ability to attack the server through an Internet-accessible login form depends on the specific implementation of the TACACS + client and should not yet be considered a universal method of operation.
Vulnerable code is present in the versions of Shrubbery Networks tac_plus up to F4.0.4.31 inclusive. On September 21, the developers released F4.0.4.32, where they fixed both found errors of the format line. The Facebook F4.0.4.28-7fb fork also contains a major vulnerable site, however, its repository was archived in August 2025 and no updates are expected for it. Elttam also warns of unknown number of assembly derivatives and embedded versions based on Cisco’s old code.
Cisco PSIRT told researchers that modern Cisco products do not use vulnerable versions of code and are not affected by the problem. CVE is not yet assigned at the time of publication. There is also no public evidence of exploitation of a new vulnerability in real attacks.
The interest of intruders in the TACACS+ infrastructure has long gone beyond the theory. China-linked Salt Typhoon operators intercepted TACACS+ traffic on compromised routers, extracted common secrets from configurations, and changed AAA parameters to move further across networks. Those attacks did not exploit the new tac_plus vulnerability, but show the value of centralized authentication systems for cyber espionage.
In August 2026, researchers also described the Fire Ant campaign, whose participants had already infiltrated directly into the tac_plus processes. The malware TacTap set introduced the library into the server, intercepted authentication sessions, and collected administrator credentials. The links between Fire Ant, Salt Typhoon and the new tac_plus error were not established.
Shrubbery tac_plus administrators are advised to upgrade to F4.0.4.32. For the archive fork of Facebook and other derivatives of the assemblies, you will need to independently correct or switch to a supported implementation. Prior to the update, the researchers advise allowing access to TCP/49 only trusted network hardware addresses and using a long random unique common secret. In the long run, it is safer to switch to TACACS+ on top of TLS 1.3, as the old traffic protection mechanism no longer meets modern security requirements.