Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2025-20188Hard-coded Credentials in Cisco IOS XE Software

Severity
10.0CRITICALNVD
EPSS
3.9%
top 11.68%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 7
Latest updateJun 12

Description

A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP file uploa

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages2 packages

CVEListV5cisco/cisco_ios_xe_software7 versions+6
NVDcisco/ios_xe7 versions+6

🔴Vulnerability Details

3
GHSA
GHSA-489q-h7v6-2626: A vulnerability in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow a2025-05-07
CVEList
CVE-2025-20188: A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco2025-05-07
VulnCheck
Cisco ios_xe Use of Hard-coded Credentials2025

💥Exploits & PoCs

1
Nuclei
Cisco IOS XE WLC - Arbitrary File Upload

🔍Detection Rules

1
Suricata
ET EXPLOIT Cisco IOS XE WLC Arbitrary File Upload Attempt (CVE-2025-20188)2025-06-12

📋Vendor Advisories

1
Cisco
Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability2025-05-07

🕵️Threat Intelligence

2
Bleepingcomputer
Exploit details for max severity Cisco IOS XE flaw now public2025-05-31
Bleepingcomputer
Cisco fixes max severity IOS XE flaw letting attackers hijack devices2025-05-08
CVE-2025-20188 — Hard-coded Credentials in Cisco | cvebase