Don't Just Read the News, Understand It.
Published loading...Updated

CVE-2025-20188: Cisco IOS XE Wireless Controller Remote File Upload Vulnerability

Summary by Horizon3.ai
CVE-2025-20188 is a critical arbitrary file upload vulnerability found in Cisco IOS XE Wireless Controller Software, including versions used in Catalyst 9800 and Embedded Wireless Controllers. It is caused by a hard-coded JSON Web Token (JWT) that allows an unauthenticated, remote attacker to send specially crafted HTTPS requests to the AP image download interface. This functionality requires the… Source
DisclaimerThis story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.

Bias Distribution

  • There is no tracked Bias information for the sources covering this story.
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

Horizon3.ai broke the news in on Thursday, May 29, 2025.
Sources are mostly out of (0)