Cisco has released a major security vulnerability advisory (CVE-2025-20334, CVSS: 8.8). This vulnerability exists in the HTTP
API subsystem of Cisco IOS XE due to insufficient input validation, allowing an attacker with administrator privileges to authenticate to the affected system via a specially crafted
API request; or allowing an unauthenticated remote attacker to induce a legitimate user with administrator privileges to click on a specially crafted link to trigger the vulnerability. If successfully exploited, the attacker may execute arbitrary commands on the affected system with root privileges.