Multiple Cisco products affected by Remote Code Execution Vulnerability (CVE-2025-20363)
– This vulnerability is due to improper validation of user-supplied input in HTTP requests.
Read MoreArticles and blog posts that relate to Cisco Systems which is a multinational technology company based in San Jose, California. Founded in 1984 by Leonard Bosack and Sandy Lerner, Cisco is a global leader in networking and cybersecurity solutions. The company designs, manufactures, and sells a wide range of networking hardware, software, and telecommunications equipment.
Cisco’s products and services are essential for building and maintaining internet infrastructure, including routers, switches, firewalls, and wireless access points. Cisco also offers solutions for network security, cloud computing, data centers, and collaboration tools such as Webex for video conferencing.
– This vulnerability is due to improper validation of user-supplied input in HTTP requests.
Read MoreCVE number = CVE-2025-20248 A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local
Read More– A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device.
Read More– A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed.
Read MoreCVE number = CVE-2025-20328 A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated,
Read MoreCVE number = CVE-2025-20241 A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexus
Read More– A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website.
Read More– A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device.
Read More– Cisco is aware of continued exploitation activity of the vulnerability that is described in this advisory and strongly recommends that customers assess their systems and upgrade to a fixed software release as soon as possible.
Read MoreCVE number = CVE-2025-20148 A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could
Read More