Cisco IOS XE Exploit: Critical Flaw Details Released
- Technical details have surfaced regarding a maximum-severity flaw, tracked as CVE-2025-20188, in Cisco IOS XE Wireless LAN Controllers (WLC).
- While the analysis by Horizon3 researchers stops short of providing a ready-to-deploy proof-of-concept remote code execution (RCE) exploit, it offers enough facts for skilled threat actors to weaponize...
- Cisco initially disclosed the critical vulnerability in its IOS XE Software for Wireless LAN Controllers on May 7, 2025.
Cisco IOS XE Wireless LAN Controllers are under siege; a critical arbitrary file upload vulnerability (CVE-2025-20188) exposes devices to significant risks. Details reveal how attackers leverage a hard-coded JWT to upload files and execute commands with root privileges. This flaw affects Catalyst 9800 Wireless Controllers and more. To safeguard your network from potential exploitation, immediate action is paramount. News Directory 3 is following the story closely. Update to patched versions (17.12.04 or later) or disable ‘Out-of-Band AP Image Download.’ Learn how to protect your network; discover the next steps to secure your infrastructure.
Cisco IOS XE Wireless LAN Controller Flaw Exposes Devices to Arbitrary File Upload attacks
updated May 31, 2025
Technical details have surfaced regarding a maximum-severity flaw, tracked as CVE-2025-20188, in Cisco IOS XE Wireless LAN Controllers (WLC). This arbitrary file upload vulnerability brings the threat of a working exploit closer to reality.
While the analysis by Horizon3 researchers stops short of providing a ready-to-deploy proof-of-concept remote code execution (RCE) exploit, it offers enough facts for skilled threat actors to weaponize the vulnerability. The immediate risk of exploitation necessitates prompt action from affected users to secure their systems.
Cisco IOS XE WLC Vulnerability Details
Cisco initially disclosed the critical vulnerability in its IOS XE Software for Wireless LAN Controllers on May 7, 2025. The flaw allows unauthenticated, remote attackers to seize control of devices.The root cause is a hard-coded JSON Web Token (JWT) that enables unauthorized file uploads, path traversal, and the execution of arbitrary commands with root privileges, Cisco said.
The vulnerability, CVE-2025-20188, poses a risk only when the ‘Out-of-Band AP Image Download’ feature is active. Affected device models include:
- Catalyst 9800-CL wireless Controllers for Cloud
- Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series switches
- Catalyst 9800 Series Wireless Controllers
- Embedded Wireless Controller on Catalyst APs
Horizon3 Analysis highlights JWT Vulnerability
Horizon3’s analysis pinpoints the vulnerability to a hardcoded JWT fallback secret (“notfound”) used by backend Lua scripts for upload endpoints, compounded by inadequate path validation. The backend relies on openresty (Lua + Nginx) scripts to validate JWT tokens and manage file uploads.Though, if the ‘/tmp/nginx_jwt_key’ file is absent, the script defaults to “notfound” as the secret for JWT verification.
this fallback mechanism allows attackers to generate valid tokens without needing any secrets,simply by using ‘HS256’ and ‘notfound.’
Horizon3’s attack exmaple involves sending an HTTP POST request with a file upload to the ‘/ap_spec_rec/upload/’ endpoint via port 8443, using filename path traversal to place a file (foo.txt) outside the intended directory.

Source: Horizon3
To elevate the arbitrary file upload vulnerability to remote code execution, attackers could overwrite configuration files used by backend services, deploy web shells, or exploit monitored files to trigger unauthorized actions.
Horizon3’s presentation involves abusing the ‘pvp.sh’ service, which monitors specific directories. By overwriting the configuration files it relies on, an attacker can trigger a reload and execute arbitrary commands.
Given the heightened risk of exploitation, upgrading to a patched version (17.12.04 or newer) is strongly advised. As an interim measure, administrators can disable the Out-of-Band AP Image Download feature to mitigate the vulnerable service.
