logo

Exploit details for max severity Cisco IOS XE flaw now public

ID: 10ec0c8c-5369-5285-83b7-1b9b840e6e01

STIX ID: report--10ec0c8c-5369-5285-83b7-1b9b840e6e01

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-05-31

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

**Executive summary:** Cisco disclosed a critical arbitrary file upload and path traversal vulnerability (CVE-2025-20188) in IOS XE Wireless LAN Controllers caused by a hard-coded JWT fallback secret ('notfound'), allowing unauthenticated file uploads and potential root remote code execution. Horizon3 published technical details showing how to craft tokens and abuse the /ap_spec_rec/upload/ endpoint to drop files and escalate to RCE; Cisco recommends updating to 17.12.04+ and disabling the Out-of-Band AP Image Download feature as a temporary workaround.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.