2025-06-02
Patch Cisco IOS XE Wireless Controllers Now
Technical details for exploiting a known vulnerability in Cisco IOS XE wireless controllers have been released; users are urged to patch affected systems as soon as possible. Cisco addressed the critical arbitrary file upload vulnerability in an update on May 7. Cisco describes the issue as "a vulnerability in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) [that] could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system." Researchers from Horizon3 published an analysis of the vulnerability that includes technical details, making the vulnerability a must-patch-now issue.
Editor's Note
This now puts us into a "fix it now" scenario as the information is now publicly available to create an exploit. At its core CVE-2025-20188 stems from a hard coded authentication token, which can only be addressed by applying the update.

Lee Neely
It's been a while since I've been at Cisco looking at the Wireless Controllers, but the last time I remember, the IOS XE one is built into the switches themselves and is not part of the WLC core product line. It's challenging for me to estimate how many of these are deployed in the wild like this. I would have assumed most companies are still using the WLC Controller model. Either way, it's not a bad idea to patch.

Moses Frost
Ugh, hard-coded credential, found, and soon to be exploited. It sure seems like a poor secure-by-design choice by the folks from Cisco, who know better. Given the CVSS rating, 10.0, it's a must-fix with a patch being available for almost a month. Let's hope that by now, everyone affected has downloaded and patched. Hey, a person can hope canÕt they?

Curtis Dukes
Read more in
BleepingComputer: Exploit details for max severity Cisco IOS XE flaw now public
SecurityWeek: Technical Details Published for Critical Cisco IOS XE Vulnerability
SCWorld: Cisco IOS XE bug rated 10.0: ‘Waiting is not an option,’ pros say
Cisco: Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability