CVE-2025-20188
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs
Description
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP file upload interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.
Weakness: CWE-798
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco IOS XE Software | Routing & Switching | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco IOS XE Software
Vendor advisory
cisco-sa-wlc-file-uplpd-rHZG9UfC
Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability
Cisco’s rating: Critical (advisory CVSS 10.0) · Published May 7, 2025 · updated Jun 6, 2025 (revision 2.2)
Bug ID: CSCwk33139
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from