CVE-2025-20188Disclosure(cisco / ios_xe)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP file upload interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ios_xe

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ios_xe

7 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-24: 1Technical Details · 2026-03-24: 103-24
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • @pedri77@pedri77
    Disclosure

    Technical details about a critical Cisco IOS XE WLC flaw (CVE-2025-20188) are now public, raising the risk of a working exploit emerging soon. Details of a critical vulnerability, tracked as CVE-2025-20188, impacting Ci... https://f.mtr.cool/agzvijlqwx

    Post summary

    The post announces that technical details of CVE-2025-20188 are now available, highlighting a potential for exploitation in the near future.

    00000131
    2.1K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSciscoios_xe17.11.1--
OSciscoios_xe17.11.99sw--
OSciscoios_xe17.12.1--
OSciscoios_xe17.12.2--
OSciscoios_xe17.12.3--
OSciscoios_xe17.13.1--
OSciscoios_xe17.14.1--

Explore more