CVE-2025-20265Patch(cisco / secure_firewall_management_center)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cisco secure_firewall_management_center systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device.  This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could exploit this vulnerability by sending crafted input when entering credentials that will be authenticated at the configured RADIUS server. A successful exploit could allow the attacker to execute commands at a high privilege level. Note: For this vulnerability to be exploited, Cisco Secure FMC Software must be configured for RADIUS authentication for the web-based management interface, SSH management, or both.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • secure_firewall_management_center

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
secure_firewall_management_center

2 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-04: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-04: 103-04
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • xkzDB@xkzdb
    Patch

    🚨 Cisco warns of max severity Secure FMC flaws giving root access Cisco has released security updates to patch two maximum-severity vulnerabilities in its Secure Firewall Management Center (FMC) software. <<<IMPORTANT>>> ⚡️ CVE-2025-20265 (CVSS 10.0): Unauthenticated remote attacker can inject arbitrary shell commands executed as root via RADIUS subsystem ⚡️ Affects FMC versions 7.0.7 and 7.7.0 if RADIUS authentication enabled for web/SSH management ⚡️ No workarounds; apply patches via regular channels or disable RADIUS ⚡️ Discovered internally by Cisco's Brandon Sakai; no known exploits Follow, repost, like, and comment on every post to help me spread awareness :)

    Post summary

    Cisco warns about a high‑severity vulnerability in Secure FMC, provides patch or RADIUS‑disable workarounds, and confirms no known exploits.

    00000120
    266 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appciscosecure_firewall_management_center7.0.7--
Appciscosecure_firewall_management_center7.7.0--

Explore more