HomeSecurityCisco fixes 35 vulnerabilities in various products

Cisco patches 35 vulnerabilities in various products

Cisco on Wednesday announced the release of fixes for 35 vulnerabilities , 26 of which are included in the semi-annual security advisory package for IOS and IOS XE .

See also: Quantum Networking: Cisco presents innovative chip and new laboratory

Cisco vulnerabilities

The IOS updates fix 1 critical and 16 high-severity vulnerabilities. The critical vulnerability, coded CVE-2025-20188 and rated CVSS 10/10, concerns an error in the Out-of-Band Access Point (AP) image capture feature of the IOS XE software.

A pre-configured JSON Web Token (JWT) allows attackers to upload files by sending properly crafted HTTP requests to the AP's image capture interface. Although the security flaw can be exploited remotely and without authentication, it only affects Wireless LAN Controllers (WLCs) that have this feature enabled. By default, this feature is disabled.

The most serious of the high-severity vulnerabilities in Cisco's semi-annual security patch could allow remote attackers to execute commands, cause a denial of service (DoS) condition, or gain elevated access privileges.

See also: Cisco warns of backdoor in CSLU

The command execution (CVE-2025-20186) and elevation of privilege (CVE-2025-20164) vulnerabilities require authentication, while the DoS bugs (CVE-2025-20154, CVE-2025-20182, and CVE-2025-20162) can be exploited by unauthorized users.

cisco intelbroker
Cisco patches 35 vulnerabilities in various products

The remaining high-severity vulnerabilities fixed in IOS and IOS XE software could, under certain circumstances, lead to DoS, elevation of privilege, or persistent code execution during system startup. The security patch also includes fixes for medium-severity vulnerabilities in IOS that could be exploited to perform cross-site request forgery (CSRF), execute SNMP commands from unauthorized sources, bypass traffic filters, read system parameters or operational data, write arbitrary files, delete users, or cause a DoS condition.

On Wednesday, Cisco also announced fixes for high-severity vulnerabilities in the Catalyst Center and the Catalyst SD-WAN Manager, which could allow attackers to modify outbound proxy settings and gain elevated privileges, respectively.

See also: Hackers target Cisco Smart Licensing Utility vulnerabilities

Additionally, updates to Catalyst Center and Catalyst SD-WAN Manager also addressed several medium severity vulnerabilities.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS