Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability (CVE-2025-20188)
CVE number = CVE-2025-20188 A vulnerability in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software
Read MoreArticles and blog posts that relate to Cisco Systems which is a multinational technology company based in San Jose, California. Founded in 1984 by Leonard Bosack and Sandy Lerner, Cisco is a global leader in networking and cybersecurity solutions. The company designs, manufactures, and sells a wide range of networking hardware, software, and telecommunications equipment.
Cisco’s products and services are essential for building and maintaining internet infrastructure, including routers, switches, firewalls, and wireless access points. Cisco also offers solutions for network security, cloud computing, data centers, and collaboration tools such as Webex for video conferencing.
CVE number = CVE-2025-20188 A vulnerability in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software
Read MoreThis vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Cisco IOS XE.
Read MoreThis vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Cisco IOS XE.
Read MoreOn April 16th 2025, a critical vulnerability in the Erlang/OTP SSH server was disclosed. This vulnerability could allow an unauthenticated, remote attacker to perform remote code execution (RCE) on an affected device.
Read MoreA vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user.
Read MoreCVE-2025-20150 – A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts.
Read MoreA vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
Read MoreA vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device.
Read MoreCVE-2024-20439 and CVE-2024-20440 – Multiple vulnerabilities in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to collect sensitive information or administer Cisco Smart Licensing Utility services on a system while the software is running.
Read MoreA vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms.
Read More