Cisco Discloses Critical RCE Flaw in Firewall Management Software
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20118 | Authenticated Command Injection in Cisco Small Business RV Series Routers CVE-2023-20118 is a command injection flaw (CWE-77) in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 routers, caused by improper validation of user input within incoming HTTP packets. An authenticated remote attacker who already holds valid administrative credentials sends a crafted HTTP request to the management interface and can execute arbitrary commands with root-level privileges, gaining full device control and access to unauthorized data. All organizations running these six small-business router models are affected, and Cisco has stated it will not release any software update, leaving only a workaround. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-03, carries a high EPSS score of 54.1%, and news reporting around that period describes campaigns (e.g., ViciousTrap, which built a global honeypot from roughly 5,300 compromised devices) abusing Cisco router flaws, with botnet operators such as PolarEdge also targeting Cisco small-business routers. These end-of-service devices are therefore under active, in-the-wild exploitation and should be treated as high-priority for mitigation. Do: No firmware fix will ever be released, so apply Cisco's workaround by disabling the affected feature or restricting the web management interface to trusted management hosts only (disable remote/internet-facing management). Check device logs and configurations for signs of compromise, including unexpected configuration changes or outbound connections indicating botnet implants. Because these routers are end-of-service, plan migration to supported models and, for federal agencies, follow BOD 22-01 mitigation guidance or discontinue use. | 7.2 | 54% | KEV |
| largetens of thousands of internet-exposed devices (order-of-magnitude estimate; at least ~5,300 already confirmed compromised in one reported campaign) | |
| CVE-2025-20265 | A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device. This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could exploit this vulnerability by sending crafted input when entering credentials that will be authenticated at the configured RADIUS server. A successful exploit could allow the attacker to execute commands at a high privilege level. Note: For this vulnerability to be exploited, Cisco Secure FMC Software must be configured for RADIUS authentication for the web-based management interface, SSH management, or both. NVD description · AI analysis pending | 10.0 | 15% |
| — |
Full article400 words · extracted from infosecurity-magazine.com · click to collapse
Cisco has disclosed a critical vulnerability in its Secure Firewall Management Center (FMC) Software.
The remote code execution (RCE) flaw, CVE-2025-20265, has a maximum CVSS severity score of 10.0. Customers have been urged to apply software updates as soon as possible to avoid potential compromise.
The vulnerability is contained in the RADIUS system implementation of Cisco FMC software. If exploited, it can allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device.
RADIUS is an access server authentication and accounting protocol used by Cisco devices, enabling secure network access by verifying user credentials and managing network resource usage.
“This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could exploit this vulnerability by sending crafted input when entering credentials that will be authenticated at the configured RADIUS server. A successful exploit could allow the attacker to execute commands at a high privilege level,” the tech giant warned in an advisory dated August 14.
The bug affects Cisco Secure FMC Software releases 7.0.7 and 7.7.0 if they have RADIUS authentication enabled.
How to Address the Firewall Management Flaw
The notification is part of a bundled publication which includes 21 Cisco Security Advisories that described 29 vulnerabilities in Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software.
Cisco has offered customers a free software update to address the specific Secure FMC flaw. Customers with service contracts that entitle them to regular software updates should obtain security fixes through their usual update channels.
There are no workarounds that address the vulnerability. However, as it can only be exploited if RADIUS authentication is configured, Cisco said customers can mitigate the issue by switching to another type of authentication, such as local user accounts, external LDAP authentication or SAML single sign-on (SSO).
The latest Cisco advisory follows a spate of reported exploitations of the firm’s products in 2025.
In July, the US Cybersecurity and Infrastructure Security Agency (CISA) added two critical flaws in Cisco Identity Services Engine (ISE) Software to its Known Exploited Vulnerabilities (KEV) catalog.
In March, the agency ordered federal government bodies to patch CVE-2023-20118, a command injection vulnerability in the web-based management interface of multiple Cisco Small Business RV Series routers.
Cisco revealed in February that Chinese state-sponsored actor Salt Typhoon gained access to US telecoms providers through Cisco devices, leveraging a custom-built utility called JumbledPath.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisco-critical-rce-flaw-firewall/