Date Posted: 2025/09/30

[Vulnerability Alert] Cisco IOS XE Has a High-Risk Security Vulnerability (CVE-2025-20334)

  • Subject: [Vulnerability Alert] Cisco IOS XE Has a High-Risk Security Vulnerability (CVE-2025-20334)
  • Content:
    • Forwarded from Taiwan Computer Network Emergency Response Team/Coordination Center TWCERTCC-200-202509-00000014
    • Cisco has released a major security vulnerability advisory (CVE-2025-20334, CVSS: 8.8). This vulnerability exists in the HTTP API subsystem of Cisco IOS XE due to insufficient input validation, allowing an attacker with administrator privileges to authenticate to the affected system via a specially crafted API request; or allowing an unauthenticated remote attacker to induce a legitimate user with administrator privileges to click on a specially crafted link to trigger the vulnerability. If successfully exploited, the attacker may execute arbitrary commands on the affected system with root privileges.

Computer and Communications Center
Network Systems Group