Today's Core Dump is brought to you by ThreatPerspective

Security Affairs

Cisco fixed a critical flaw in its IOS XE Wireless Controller

Cisco addressed a flaw in its IOS XE Wireless Controller that could enable an unauthenticated, remote attacker to upload arbitrary files. Cisco released software updates to address a vulnerability, tracked as CVE-2025-20188 (CVSS score 10), in IOS XE Wireless Controller. An unauthenticated, remote attacker can exploit the flaw to load arbitrary files to a vulnerable system. […] Cisco addressed a flaw in its IOS XE Wireless Controller that could enable an unauthenticated, remote attacker to upload arbitrary files. Cisco released software updates to address a vulnerability, tracked as CVE-2025-20188 (CVSS score 10), in IOS XE Wireless Controller. An unauthenticated, remote attacker can exploit the flaw to load arbitrary files to a vulnerable system. An attacker can exploit this flaw by sending crafted HTTPS requests to the AP image download interface, potentially gaining root access and executing arbitrary commands. “A vulnerability in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system.” reads the advisory. “This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP image download interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.” The flaw can be exploited only if the Out-of-Band AP Image Download feature is enabled, however the IT giant pointed out that the flaw is disabled by default. The vulnerability impacts the following products: Catalyst 9800-CL Wireless Controllers for Cloud Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches Catalyst 9800 Series Wireless Controllers Embedded Wireless Controller on Catalyst APs To check if a device is affected, run show running-config | include ap upgrade. If it returns ap upgrade method https, the Out-of-Band AP Image Download feature is enabled. “With this feature disabled, AP image download will use the CAPWAP method for the AP image update feature, and this does not impact the AP client state.” continues the advisory. The company states that no workaround exists, but the vulnerability can be mitigated by disabling the Out-of-Band AP Image Download feature. Cisco urges this until a fix is applied, but users must assess the impact on their environment first. The Cisco Product Security Incident Response Team (PSIRT) is not aware of attacks in the wild exploiting this vulnerability. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs hacking, IOS XE Wireless Controller)

Published: 2025-05-08T13:13:41











© Segmentation Fault . All rights reserved.

Privacy | Terms of Use | Contact Us