peter bassill · operator
$ cve CVE-2025-20188 JSON

CVE-2025-20188

10.0
CRITICAL · CVSS 3.1 · EPSS 27.5% (pctl 98)

Patch early

EPSS 27.5% — above the 10% action threshold.

Description

A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP file upload interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS27.49% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2025-05-07
Last modified2026-06-17

Affected (1)

VendorProduct
ciscoios xe

References

→ the Explorer  ·  watch your stack  ·  NVD