Security Affairs newsletter Round 527 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20188 | Unauthenticated File Upload to Root RCE in Cisco IOS XE WLC (Hard-coded JWT) CVE-2025-20188 is a critical (CVSS 10.0) vulnerability in the Out-of-Band AP Image Download, Clean Air Spectral Recording, and client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs), caused by a hard-coded JSON Web Token (JWT) present on affected systems (CWE-798). An unauthenticated, remote attacker can trigger it by sending crafted HTTPS requests to the AP file upload interface, leveraging the hard-coded JWT. A successful exploit lets the attacker upload arbitrary files, perform path traversal, and execute arbitrary commands with root privileges on the controller. Any organization running an affected IOS XE release on a WLC is affected, with internet-reachable HTTPS management interfaces at highest risk; the source data does not enumerate specific affected version ranges. Cisco has shipped a patch, a public technical analysis/PoC exists, the flaw is not in CISA's KEV, and EPSS assigns a 27.1% probability of exploitation within 30 days (98th percentile), indicating elevated but not yet confirmed in-the-wild exploitation. Do: Upgrade affected WLCs to a fixed IOS XE release listed in Cisco's advisory; the provided data contains no version numbers, so rely on the advisory's fixed-release table rather than this summary. As an interim measure, restrict internet access to the controller's HTTPS management/AP file upload interface and consider disabling the affected features (notably Out-of-Band AP Image Download) where feasible. Because successful exploitation grants root-level command execution, hunt for indicators such as unexpected uploaded files or unexplained configuration changes, and monitor for potential KEV listing given the 27.1% EPSS score. | 10.0 | 27% | PoC |
| largeon the order of 10k-100k deployed IOS XE-based WLC systems, likely tens of thousands of internet-exposed controllers (estimate) |
Full article501 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Websites selling hacking tools to cybercriminals seized
Alleged Conti, TrickBot Gang Leader Unmasked
Key service for malware developers taken offline
Hospitals in Maine, New Hampshire limit services after cyberattack on Catholic health org
U.S. Government seizes approximately 145 criminal marketplace domains
Interlock ransomware claims Kettering Health breach, leaks stolen data
#StopRansomware: Play Ransomware
Maxim Alexandrovich Rudometov & RedLine
The SEC Pinned Its Hack on a Few Hapless Day Traders. The Full Story Is Far More Troubling
Ross Ulbricht Got a $31 Million Donation From a Dark Web Dealer, Crypto Tracers Suspect
Ransomware gang claims responsibility for Kettering Health hack
Malware
Pure Crypter Malware Analysis: 99 Problems but Detection Ain’t One
Attacker exploits misconfigured AI tool to run AI-generated payload
Malicious Ruby Gems Exfiltrate Telegram Tokens and Messages Following Vietnam Ban
From open-source to open threat: Tracking Chaos RAT’s evolution
Home Internet Connected Devices Facilitate Criminal Activity
Hacking
vBulletin replaceAdTemplate Exploited in the Wild
Don’t Call That “Protected” Method: Dissecting an N-Day vBulletin RCE
Cisco IOS XE WLC Arbitrary File Upload Vulnerability (CVE-2025-20188) Analysis
Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU
Preinstalled Apps on Ulefone, Krüger&Matz Phones Let Any App Reset Device, Steal PIN
DevOps Tools Targeted for Cryptojacking
Critical 10-Year-Old Roundcube Webmail Bug Allows Authenticated Users Run Malicious Code
Critical Fortinet flaws now exploited in Qilin ransomware attacks
Riding The Time Machine: Journey Through An Old vBulletin PHP Object Injection
Intelligence and Information Warfare
Eight things we learned from WhatsApp vs. NSO Group spyware lawsuit
Ukraine Hacks Tupolev, Exposes Russia’s Strategic Bomber Secrets
Newly identified wiper malware “PathWiper” targets critical infrastructure in Ukraine
Justice Department accuses two Chinese researchers of smuggling ‘potential agroterrorism weapon’ into US
Uncle Sam moves to seize $7.7M laundered by North Korean IT worker ring
The Bitter End: Unraveling Eight Years of Espionage Antics – Part Two
Cybersecurity
Sustaining Digital Certificate Security – Upcoming Changes to the Chrome Root Store
Announcing a new strategic collaboration to bring clarity to threat actor naming
NSO Group asks judge for new trial, calling $167 million in damages ‘outrageous’
Victoria’s Secret says it will postpone earnings report after recent security breach
Largest ever data leak exposes over 4 billion user records
Australian ransomware victims now must tell the government if they pay up
EU takes a step further in cybersecurity crisis management
Cyber Attacks Are Up 47% in 2025 – AI is One Key Factor
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/178759/uncategorized/security-affairs-newsletter-round-527-by-pierluigi-paganini-international-edition.html