Researchers have discovered an Arbitrary File Upload vulnerability (CVE-2025-20188) in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software for Wireless
LAN Controllers (WLCs). This vulnerability allows unauthenticated remote attackers to upload backdoor programs to execute arbitrary code.