ZeroHour

CVE-2025-20188

PoC large

Unauthenticated File Upload to Root RCE in Cisco IOS XE WLC (Hard-coded JWT)

CVSS 3.1
10.0 critical
EPSS
27%p98
Published
()
Modified
AI analysis

CVE-2025-20188 is a critical (CVSS 10.0) vulnerability in the Out-of-Band AP Image Download, Clean Air Spectral Recording, and client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs), caused by a hard-coded JSON Web Token (JWT) present on affected systems (CWE-798). An unauthenticated, remote attacker can trigger it by sending crafted HTTPS requests to the AP file upload interface, leveraging the hard-coded JWT. A successful exploit lets the attacker upload arbitrary files, perform path traversal, and execute arbitrary commands with root privileges on the controller. Any organization running an affected IOS XE release on a WLC is affected, with internet-reachable HTTPS management interfaces at highest risk; the source data does not enumerate specific affected version ranges. Cisco has shipped a patch, a public technical analysis/PoC exists, the flaw is not in CISA's KEV, and EPSS assigns a 27.1% probability of exploitation within 30 days (98th percentile), indicating elevated but not yet confirmed in-the-wild exploitation.

What to do: Upgrade affected WLCs to a fixed IOS XE release listed in Cisco's advisory; the provided data contains no version numbers, so rely on the advisory's fixed-release table rather than this summary. As an interim measure, restrict internet access to the controller's HTTPS management/AP file upload interface and consider disabling the affected features (notably Out-of-Band AP Image Download) where feasible. Because successful exploitation grants root-level command execution, hunt for indicators such as unexpected uploaded files or unexplained configuration changes, and monitor for potential KEV listing given the 27.1% EPSS score.

Affected
Cisco IOS XE Software for Wireless LAN Controllers (WLCs)
Estimated exposure
largeon the order of 10k-100k deployed IOS XE-based WLC systems, likely tens of thousands of internet-exposed controllers (estimate) — Cisco is the leading enterprise WLAN controller vendor and IOS XE has an installed base in the millions, but only WLC deployments expose the vulnerable features, and historical public internet scans of IOS XE devices (tens of thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP file upload interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.

Vendors
cisco
Products
ios xe
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news