logo

Exploitation Risk Grows for Critical Cisco Bug

ID: 9f688bf2-729e-57a2-8674-5381bfbfacea

STIX ID: report--9f688bf2-729e-57a2-8674-5381bfbfacea

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-06-02

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

A public analysis disclosed technical details for CVE-2025-20188, a maximum-severity (CVSS 10) arbitrary file upload flaw in Cisco IOS XE Wireless LAN Controllers caused by a hard-coded JSON Web Token and weak file validation; researchers showed how the issue can be turned into remote code execution, increasing risk after the disclosure and prompting urgent patching or disabling the affected feature.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.