CVE-2025-20265
published 2025-08-14CVE-2025-20265: A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote…
PriorityP184critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
14.78%
96.3th percentile
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device.
This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could exploit this vulnerability by sending crafted input when entering credentials that will be authenticated at the configured RADIUS server. A successful exploit could allow the attacker to execute commands at a high privilege level.
Note: For this vulnerability to be exploited, Cisco Secure FMC Software must be configured for RADIUS authentication for the web-based management interface, SSH management, or both.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector targets the RADIUS authentication phase of Cisco Secure FMC — monitor for crafted/anomalous credential input (shell metacharacters, command injection payloads) submitted to the FMC web-based management interface or SSH management interface when RADIUS authentication is configured. ↗
- →Scope detection to Cisco Secure FMC instances where RADIUS authentication is enabled for the web-based management interface, SSH management, or both — these are the only attack surfaces exposed by this vulnerability. ↗
- →Successful exploitation results in arbitrary shell command execution at a high privilege level — alert on unexpected privileged shell processes spawned from FMC authentication/RADIUS subsystem processes. ↗
- →Prioritize detection on FMC versions 7.0.7 and 7.7.0 with RADIUS authentication enabled, as these are the confirmed affected versions. ↗
- →Track Cisco Bug ID CSCwo91250 for vendor threat intelligence updates and any future proof-of-concept indicators associated with this vulnerability. ↗
- ·Vulnerability is only exploitable when RADIUS authentication is configured for the FMC web-based management interface, SSH management, or both — deployments using other authentication methods are not affected. ↗
- ·No workarounds are available; remediation requires applying Cisco's released software updates. ↗
- ·As of the reporting date, no active exploitation in the wild has been observed. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability
vendor_cisco·2025-08-14·CVSS 10.0
CVE-2025-20265 [CRITICAL] CWE-74 Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability
Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device.
This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could exploit this vulnerability by sending crafted input when entering credentials that will be authenticated at the configured RADIUS server. A successful exploit could allow the attacker to execute commands at a high privilege level.
Note: For this vulnerability to be exploited, Cisco Secure FMC Software must be configured for RADIUS authentication for the w
Cisco
Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20265 Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability
CVE-2025-20265: Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device. This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could exploit this vulnerability by sending crafted input when entering credentials that will be authenticated at the configured RADIUS server. A successful exploit could allow the attacker to execute commands at a high privilege level. Note: For this vulnerability to be exploited, Cisco Secure FMC Software must be configured for RADIUS authentica
GHSA
GHSA-rc2h-jcr9-jm85: A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remot
ghsa_unreviewed·2025-08-14
CVE-2025-20265 [CRITICAL] CWE-74 GHSA-rc2h-jcr9-jm85: A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remot
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device.
This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could exploit this vulnerability by sending crafted input when entering credentials that will be authenticated at the configured RADIUS server. A successful exploit could allow the attacker to execute commands at a high privilege level.
Note: For this vulnerability to be exploited, Cisco Secure FMC Software must be configured for RADIUS authentication for the web-based management interface, SSH management, or both.
No detection rules found.
No public exploits indexed.
Checkpoint
18th August – Threat Intelligence Report
blogs_checkpoint·2025-08-18
CVE-2025-30388 18th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 18th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 18th August, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The Canadian House of Commons has suffered a data breach. The incident resulted in unauthorized access to a database containing employees’ names, office locations, email addresses, and information on House-managed computers and mobile devices, reportedly due to vulnerability in Microsoft software.
The Office of the Pennsyl
Bleepingcomputer
Cisco warns of max severity flaw in Firewall Management Center
blogs_bleepingcomputer·2025-08-15·CVSS 10.0
[CRITICAL] Cisco warns of max severity flaw in Firewall Management Center
## Cisco warns of max severity flaw in Firewall Management Center
## Bill Toulas
Cisco is warning about a critical remote code execution (RCE) vulnerability in the RADIUS subsystem of its Secure Firewall Management Center (FMC) software.
Cisco FCM is a management platform for the vendor’s Secure Firewall products, which provides a centralized web or SSH-based interface to allow administrators to configure, monitor, and update Cisco firewalls.
RADIUS in FMC is an optional external authentication method that permits connecting to a Remote Authentication Dial-In User Service server instead of local accounts.
This configuration is commonly used in enterprise and government networks where administrators want centralized login control and accounting for network device access.
The recently
Greynoiseio
NoiseLetter March 2026
blogs_greynoiseio
NoiseLetter March 2026
Events, events… and yes, even more events. 🌍 GreyNoise has been on the move. March kept us busy with stops at eCrimes in London and SecIT in Hanover—but we’re just getting started. Over the next few months, we’ll be hitting the road for CrowdStrike CrowdTours across eight cities, heading to Glasgow to speak and sponsor CyberUK, and making our way to Tampa for H-ISAC. If you’ll be at any of these (or nearby), we’d love to connect.
And while we’ve been racking up miles, we haven’t slowed down on the research front. We’ve just released some exciting new findings—with even more coming in the next few weeks—so keep an eye out.
Thanks, as always, for being part of the GreyNoise community.
Featured
About this new report
Every enterprise firewall processes traffic from residential IP space. T
Recorded Future
August 2025 CVE Landscape
blogs_recorded_future·CVSS 8.8
[HIGH] August 2025 CVE Landscape
# August 2025 CVE Landscape
In August 2025, Recorded Future’s Insikt Group® identified eighteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the 22 identified in July.
However, the number of Very Critical vulnerabilities has remained the same (16) compared to July. These vulnerabilities have affected the following vendors: Trend Micro, WinRAR, N-able, Cisco, Apple, Citrix, FreePBX, Git, Microsoft, D-Link, and Fortinet.
August was dominated by Citrix and D-Link flaws, which represented six of the eighteen vulnerabilities. Threat actors actively exploited Citrix NetScaler ADC, NetScaler Gateway, and Citrix Session Recording products, as well as D-Link DNR-322L and DCS-2530L routers.
Recorded Future Insikt Group’s CVE Findings fro
Wiz
CVE-2026-20131 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2026-20131 [CRITICAL] CVE-2026-20131 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20131 :
Cisco Secure Firewall Management Center vulnerability analysis and mitigation
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root.
Note: If the FMC management interface does not have public internet access, the attack surface that is associated with
Recorded Future
August 2025 CVE Landscape
blogs_recorded_future·CVSS 8.8
[HIGH] August 2025 CVE Landscape
## August 2025 CVE Landscape
In August 2025, Recorded Future’s Insikt Group ® identified eighteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the 22 identified in July.
However, the number of Very Critical vulnerabilities has remained the same (16) compared to July. These vulnerabilities have affected the following vendors: Trend Micro, WinRAR, N-able, Cisco, Apple, Citrix, FreePBX, Git, Microsoft, D-Link, and Fortinet.
August was dominated by Citrix and D-Link flaws, which represented six of the eighteen vulnerabilities. Threat actors actively exploited Citrix NetScaler ADC, NetScaler Gateway, and Citrix Session Recording products, as well as D-Link DNR-322L and DCS-2530L routers.
Recorded Future Insikt Group’s CVE Findings f
2025-08-14
Published