logo

Cisco fixes max severity IOS XE flaw letting attackers hijack devices

ID: e8d65c64-e75f-545c-86bd-9dba7ff63f04

STIX ID: report--e8d65c64-e75f-545c-86bd-9dba7ff63f04

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-05-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cisco published a critical advisory for a hard-coded JWT vulnerability (CVE-2025-20188, CVSS 10.0) in IOS XE Wireless LAN Controllers that allows unauthenticated remote attackers to upload files, perform path traversal, and execute arbitrary commands as root via the Out-of-Band AP Image Download feature; affected devices include Catalyst 9800 series and embedded wireless controllers. The feature is disabled by default but may be enabled in some deployments; Cisco has released patches and advises applying updates or disabling the feature because no workaround exists, and there are no confirmed active exploitations at this time.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.