cbcvebase.
CVE-2025-20265
published 2025-08-14

CVE-2025-20265: A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote…

PriorityP184critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
14.78%
96.3th percentile
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device. This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could exploit this vulnerability by sending crafted input when entering credentials that will be authenticated at the configured RADIUS server. A successful exploit could allow the attacker to execute commands at a high privilege level. Note: For this vulnerability to be exploited, Cisco Secure FMC Software must be configured for RADIUS authentication for the web-based management interface, SSH management, or both.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector targets the RADIUS authentication phase of Cisco Secure FMC — monitor for crafted/anomalous credential input (shell metacharacters, command injection payloads) submitted to the FMC web-based management interface or SSH management interface when RADIUS authentication is configured.
  • Scope detection to Cisco Secure FMC instances where RADIUS authentication is enabled for the web-based management interface, SSH management, or both — these are the only attack surfaces exposed by this vulnerability.
  • Successful exploitation results in arbitrary shell command execution at a high privilege level — alert on unexpected privileged shell processes spawned from FMC authentication/RADIUS subsystem processes.
  • Prioritize detection on FMC versions 7.0.7 and 7.7.0 with RADIUS authentication enabled, as these are the confirmed affected versions.
  • Track Cisco Bug ID CSCwo91250 for vendor threat intelligence updates and any future proof-of-concept indicators associated with this vulnerability.
  • ·Vulnerability is only exploitable when RADIUS authentication is configured for the FMC web-based management interface, SSH management, or both — deployments using other authentication methods are not affected.
  • ·No workarounds are available; remediation requires applying Cisco's released software updates.
  • ·As of the reporting date, no active exploitation in the wild has been observed.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.