Target Industry

Indiscriminate, opportunistic targeting.

Overview

A critical vulnerability has been discovered in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs). This feature, which allows secure and efficient firmware updates for access points via HTTPS, is tracked as CVE-2025-20188 with a CVSS score of 10.0. The vulnerability allows unauthenticated remote threat actors to upload arbitrary files and execute commands with root privileges on affected systems.  

Impact

The impact of CVE-2025-20188 is significant, since it can lead to unauthorised access, data breaches, and potential disruption of services. Organisations may even face financial losses due to operational downtime, costs associated with incident response, and potential regulatory fines 

Affected Products

  • Catalyst 9800-CL Wireless Controllers for Cloud 
  • Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches 
  • Catalyst 9800 Series Wireless Controllers 
  • Embedded Wireless Controller on Catalyst APs 

Exploitation

Exploitation of CVE-2025-20188 involves sending crafted HTTPS requests to the AP image download interface, allowing threat actors to upload arbitrary files and execute commands. The vulnerability is particularly dangerous when the Out-of-Band AP Image Download feature is enabled, which is not the default setting. Threat actors can leverage a hard-coded JSON Web Token (JWT) fallback secret to bypass authentication and gain root access.  

Containment, Mitigations & Remediations

To mitigate the risks associated with CVE-2025-20188, it is highly recommended for organisations to take the following steps:  

  • Upgrade to the latest version of IOS XE Software 
  • Disable the Out-of-Band AP Image Download feature as a temporary workaround 
  • Regularly monitor and update systems to ensure they are patched against known vulnerabilities 
  • Implement strict access controls to limit exposure to vulnerable devices. 

Threat Landscape

The threat landscape surrounding CVE-2025-20188 is marked by an increasing number of cyber threats targeting network infrastructure. Threat actors are increasingly exploiting known vulnerabilities to gain access to sensitive systems, often using automated tools to exploit weaknesses. Some of the attacks on common vulnerability exposures (CVEs) are part of a chain attack, which involves multiple stages of exploitation to achieve a broader objective, such as gaining persistent access, exfiltrating data, or disrupting services. The motivations behind these attacks can range from financial gain to espionage and disruption of services. 

Threat Group

At the time of writing, there are no threat groups associated with CVE-2025-20188. 

Further Information

Cisco Security Advisory  

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content