Categories
News Review

Google Gemini now automatically summarises your Gmail emails

Categories
News Review

Experts published a detailed analysis of Cisco IOS XE WLC flaw CVE-2025-20188

Technical details about a critical Cisco IOS XE WLC flaw (CVE-2025-20188) are now public, raising the risk of a working exploit emerging soon.

Details of a critical vulnerability, tracked as CVE-2025-20188, impacting Cisco IOS XE WLC are now public, raising the risk of exploitation.

In early May, Cisco released software updates to address the vulnerability CVE-2025-20188 (CVSS score 10). An unauthenticated, remote attacker can exploit the flaw to load arbitrary files to a vulnerable system.

An attacker can exploit this flaw by sending crafted HTTPS requests to the AP image download interface, potentially gaining root access and executing arbitrary commands.

“A vulnerability in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system.” reads the advisory. “This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP image download interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.”

The flaw can be exploited only if the Out-of-Band AP Image Download feature is enabled, however the IT giant pointed out that the flaw is disabled by default.

The vulnerability impacts the following products:

  • Catalyst 9800-CL Wireless Controllers for Cloud
  • Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches
  • Catalyst 9800 Series Wireless Controllers
  • Embedded Wireless Controller on Catalyst APs

To check if a device is affected, run show running-config | include ap upgrade. If it returns ap upgrade method https, the Out-of-Band AP Image Download feature is enabled.

“With this feature disabled, AP image download will use the CAPWAP method for the AP image update feature, and this does not impact the AP client state.” continues the advisory.

The company states that no workaround exists, but the vulnerability can be mitigated by disabling the Out-of-Band AP Image Download feature. Cisco urges this until a fix is applied, but users must assess the impact on their environment first.

At the time the flaw was disclosed, the Cisco Product Security Incident Response Team (PSIRT) stated it was not aware of any active exploitation in the wild.

Horizon3 researchers discovered the vulnerability in Cisco IOS XE WLC and reported that it is caused by a hardcoded fallback secret (“notfound”) and weak path validation. If the system’s JWT key file is missing, it defaults to using “notfound” to verify tokens, making it easy for attackers to create valid tokens without knowing any real secret. By targeting a file upload feature on port 8443, attackers can sneak files outside the intended directory. This loophole can then be used to gain remote code execution by overwriting configuration files or hijacking services like pvp.sh that automatically act on certain files.

“After digging through those services, we discovered an internal process management service (pvp.sh) that waits for files to be written to a specific directory. Once a change is detected, it can trigger a service reload based on the commands specified in the service’s config file.” reads the report published by Horizon3. “In short, for RCE we’ll need to…

  • … overwrite the existing config file with our own commands.
  • … upload a new file to cause the services to be reloaded.
  • … check if we succeeded.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Cisco IOS XE WLC)

The post Experts published a detailed analysis of Cisco IOS XE WLC flaw CVE-2025-20188 first appeared on Audio Posts – audio-posts.com.

Categories
News Review

Украинская делегация прибыла на переговоры с Россией в Стамбул. СБУ, которая организовала удары по российским авиабазам в воскресенье, представляет заместитель председателя службы Александр Поклад. smarturl.click/p25eb

Categories
News Review

Citi names Bank of America veteran Zhang as new China country head reut.rs/43wDYKU reut.rs/43wDYKU

Categories
News Review

Air Traffic Control: Last Week Tonight with John Oliver (HBO)

John Oliver discusses the working conditions of air traffic controllers, why those conditions are impacting us all, and – for those under 30 – what a “floppy…

Categories
News Review

Japan factory declines slow in May but tariff worries persist, PMI shows reut.rs/3HzVUwR reut.rs/3HzVUwR

Categories
News Review

Путин в панике: звонок в США после атаки — “соболезнуем”, ответил Вашингтон / Сазонов

Кирил Сазонов в Telegram: https://t.me/KirilovolodimirovichRU – Звонок из Москвы в Вашингтон после удара по российским аэродромам: США выразили соболезновани…

Categories
News Review

⚡️ Ukrainian delegates arrive in Istanbul for next round of peace talks with Russia. Ukrainain officials arrived in Istanbul for peace talks with Russia, which are scheduled for the afternoon of June 2, Ukrinform reported, citing the Foreign Ministry. kyivindependent.com/istanbul-talks…

Categories
News Review

Ukrainian delegates arrive in Istanbul for next round of peace talks with Russia

The negotiations follow the first round of Istanbul talks, which concluded on May 16 with an agreement on the largest prisoner exchange of the war but without any progress toward a peace deal.
Categories
News Review

China robotaxis, Indian pharma among hedge fund top picks at Sohn Hong Kong reut.rs/4dDRIYY reut.rs/4dDRIYY