On May 8, 2025, Cisco disclosed a serious vulnerability in Cisco IOS XE affecting wireless controllers (WLC). This vulnerability, identified as CVE-2025-20188, received a critical score of 10.0 on the CVSSv3.x scale. It allows attackers to exploit the system by uploading files, executing path traversal attacks, and running arbitrary commands with root privileges. This can happen if the "download AP images out-of-band" feature is enabled, which is not the default configuration.
Affected Products
The vulnerability impacts various Cisco IOS XE implementations:
- Catalyst 9800 Cloud Wireless Controllers
- Catalyst 9800 Embedded Wireless Controllers for Catalyst Series 9300, 9400, and 9500 switches
- Catalyst 9800 Series Wireless Controllers
- Integrated Wireless Controller in Catalyst Access Points
For more details on the vulnerable software, users are advised to refer to the Cybersecurity Advisories and Software Assurance File (CSAF) linked in Cisco’s security advisory.
Recommendations
The Computer Emergency Response Team for Sweden (CERT-SE) strongly recommends immediate updates to all affected products and adherence to Cisco’s instructions for remediation.