Cyber Security News

Cisco IOS XE Wireless Controllers Vulnerability Enables Full Device Control for Attackers

Cisco has disclosed a critical security vulnerability in its IOS XE Wireless LAN Controllers that could allow unauthorized attackers to gain complete control of affected devices.

The flaw, assigned the maximum severity rating of 10.0, enables unauthenticated remote attackers to upload arbitrary files, traverse directories, and execute commands with root privileges on affected systems.

The vulnerability, tracked as CVE-2025-20188, resides in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs).

According to Cisco’s security advisory released on May 7, the flaw stems from “the presence of a hard-coded JSON Web Token (JWT) on an affected system”.

Security researchers note that attackers can exploit this vulnerability by sending specially crafted HTTPS requests to the AP image download interface.

When successfully exploited, attackers gain the ability to upload malicious files to arbitrary locations and execute commands with the highest system privileges.

“This vulnerability represents a significant risk to enterprise networks using affected Cisco wireless controllers,” said a cybersecurity expert familiar with the issue. “The combination of remote access, no authentication requirements, and root-level command execution makes this flaw particularly dangerous.”

Affected Products

The vulnerability affects several Cisco products running vulnerable versions of IOS XE Software with the Out-of-Band AP Image Download feature enabled:

  • Catalyst 9800-CL Wireless Controllers for Cloud
  • Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches
  • Catalyst 9800 Series Wireless Controllers
  • Embedded Wireless Controller on Catalyst APs

Administrators can determine if their devices are vulnerable by using the command “show running-config | include ap upgrade” – if it returns “ap upgrade method https,” the device is affected.

Cisco has released software updates that address this vulnerability, and customers are strongly urged to upgrade immediately. The company states there are no workarounds for this issue, but as a temporary mitigation, administrators can disable the vulnerable feature.

“Organizations should prioritize patching this vulnerability immediately,” said another security analyst. “In environments where immediate patching isn’t possible, disabling the Out-of-Band AP Image Download feature is critical until updates can be applied.”

Security bulletin information indicates the vulnerability was discovered internally by X.B. of the Cisco Advanced Security Initiatives Group during security testing. According to Cisco’s advisory, there is currently no evidence of active exploitation in the wild.

This vulnerability disclosure comes as part of Cisco’s May 2025 Semiannual IOS and IOS XE Software Security Advisory Bundled Publication, which includes fixes for multiple security issues in Cisco products.

Vulnerability Attack Simulation on How Hackers Rapidly Probe Websites for Entry Points – Free Webinar

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

AWS Automatically Quarantines Exposed IAM Keys Within 10 Seconds of GitHub Leak

Amazon Web Services can move from detection to containment in seconds when an Identity and…

23 minutes ago

Claude Code Agent Allegedly Deletes 48,000 Files in 103 Seconds

A Claude Code user has reported a severe data-loss incident in which an autonomous coding…

30 minutes ago

Microsoft Entra ID to Block SMS First-Factor Sign-Ins Worldwide in February 2027

Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide and requires…

2 hours ago

Microsoft Investigating Teams Calling Issue Blocking Users From Making or Receiving Calls

Microsoft is investigating a service incident that is preventing some users from placing or receiving…

2 hours ago

PAYLOAD Ransomware Hijacks Active Directory GPO to Disrupt Entire Windows Domain Without Encryption

A PAYLOAD ransomware attack used Active Directory Group Policy Objects to disrupt an entire Windows…

3 hours ago

Malicious npm Package With 2 Million Downloads Hides Malware in Runtime Code

A malicious npm package that appeared to be an ordinary data-indexing tool has exposed a…

3 hours ago