Cisco has disclosed a critical security vulnerability in its IOS XE Wireless LAN Controllers that could allow unauthorized attackers to gain complete control of affected devices.
The flaw, assigned the maximum severity rating of 10.0, enables unauthenticated remote attackers to upload arbitrary files, traverse directories, and execute commands with root privileges on affected systems.
The vulnerability, tracked as CVE-2025-20188, resides in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs).
According to Cisco’s security advisory released on May 7, the flaw stems from “the presence of a hard-coded JSON Web Token (JWT) on an affected system”.
Security researchers note that attackers can exploit this vulnerability by sending specially crafted HTTPS requests to the AP image download interface.
When successfully exploited, attackers gain the ability to upload malicious files to arbitrary locations and execute commands with the highest system privileges.
“This vulnerability represents a significant risk to enterprise networks using affected Cisco wireless controllers,” said a cybersecurity expert familiar with the issue. “The combination of remote access, no authentication requirements, and root-level command execution makes this flaw particularly dangerous.”
The vulnerability affects several Cisco products running vulnerable versions of IOS XE Software with the Out-of-Band AP Image Download feature enabled:
Administrators can determine if their devices are vulnerable by using the command “show running-config | include ap upgrade” – if it returns “ap upgrade method https,” the device is affected.
Cisco has released software updates that address this vulnerability, and customers are strongly urged to upgrade immediately. The company states there are no workarounds for this issue, but as a temporary mitigation, administrators can disable the vulnerable feature.
“Organizations should prioritize patching this vulnerability immediately,” said another security analyst. “In environments where immediate patching isn’t possible, disabling the Out-of-Band AP Image Download feature is critical until updates can be applied.”
Security bulletin information indicates the vulnerability was discovered internally by X.B. of the Cisco Advanced Security Initiatives Group during security testing. According to Cisco’s advisory, there is currently no evidence of active exploitation in the wild.
This vulnerability disclosure comes as part of Cisco’s May 2025 Semiannual IOS and IOS XE Software Security Advisory Bundled Publication, which includes fixes for multiple security issues in Cisco products.
Vulnerability Attack Simulation on How Hackers Rapidly Probe Websites for Entry Points – Free Webinar
Amazon Web Services can move from detection to containment in seconds when an Identity and…
A Claude Code user has reported a severe data-loss incident in which an autonomous coding…
Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide and requires…
Microsoft is investigating a service incident that is preventing some users from placing or receiving…
A PAYLOAD ransomware attack used Active Directory Group Policy Objects to disrupt an entire Windows…
A malicious npm package that appeared to be an ordinary data-indexing tool has exposed a…