Cisco on Wednesday announced the release of fixes for 35 vulnerabilities , 26 of which are included in the semi-annual security advisory package for IOS and IOS XE .
See also: Quantum Networking: Cisco presents innovative chip and new laboratory

The IOS updates fix 1 critical and 16 high-severity vulnerabilities. The critical vulnerability, coded CVE-2025-20188 and rated CVSS 10/10, concerns an error in the Out-of-Band Access Point (AP) image capture feature of the IOS XE software.
A pre-configured JSON Web Token (JWT) allows attackers to upload files by sending properly crafted HTTP requests to the AP's image capture interface. Although the security flaw can be exploited remotely and without authentication, it only affects Wireless LAN Controllers (WLCs) that have this feature enabled. By default, this feature is disabled.
The most serious of the high-severity vulnerabilities in Cisco's semi-annual security patch could allow remote attackers to execute commands, cause a denial of service (DoS) condition, or gain elevated access privileges.
See also: Cisco warns of backdoor in CSLU
The command execution (CVE-2025-20186) and elevation of privilege (CVE-2025-20164) vulnerabilities require authentication, while the DoS bugs (CVE-2025-20154, CVE-2025-20182, and CVE-2025-20162) can be exploited by unauthorized users.

The remaining high-severity vulnerabilities fixed in IOS and IOS XE software could, under certain circumstances, lead to DoS, elevation of privilege, or persistent code execution during system startup. The security patch also includes fixes for medium-severity vulnerabilities in IOS that could be exploited to perform cross-site request forgery (CSRF), execute SNMP commands from unauthorized sources, bypass traffic filters, read system parameters or operational data, write arbitrary files, delete users, or cause a DoS condition.
On Wednesday, Cisco also announced fixes for high-severity vulnerabilities in the Catalyst Center and the Catalyst SD-WAN Manager, which could allow attackers to modify outbound proxy settings and gain elevated privileges, respectively.
See also: Hackers target Cisco Smart Licensing Utility vulnerabilities
Additionally, updates to Catalyst Center and Catalyst SD-WAN Manager also addressed several medium severity vulnerabilities.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
