CVE-2025-20188

A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP file upload interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:cisco:ios_xe:17.11.1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.11.99sw:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.13.1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.12.3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.12.2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.12.1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.14.1:*:*:*:*:*:*:*

History

23 Jun 2025, 15:15

Type Values Removed Values Added
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC - () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC - Vendor Advisory
References () https://horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-wlc-arbitrary-file-upload-vulnerability-cve-2025-20188-analysis/ - () https://horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-wlc-arbitrary-file-upload-vulnerability-cve-2025-20188-analysis/ - Exploit, Third Party Advisory
First Time Cisco ios Xe
Cisco
CPE cpe:2.3:o:cisco:ios_xe:17.11.1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.12.1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.13.1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.12.3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.14.1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.12.2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:17.11.99sw:*:*:*:*:*:*:*

06 Jun 2025, 17:15

Type Values Removed Values Added
Summary A vulnerability in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP image download interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges. Note: For exploitation to be successful, the Out-of-Band AP Image Download feature must be enabled on the device. It is not enabled by default. A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP file upload interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.

04 Jun 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : unknown
References
  • () https://horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-wlc-arbitrary-file-upload-vulnerability-cve-2025-20188-analysis/ -
CWE CWE-798

07 May 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-07 18:15

Updated : 2025-06-23 15:15


NVD link : CVE-2025-20188

Mitre link : CVE-2025-20188


JSON object : View

Products Affected

cisco

  • ios_xe
CWE

No CWE.