VDB

CISCO-SA-WLC-FILE-UPLPD-RHZG9UFC

CISCO-SA-WLC-FILE-UPLPD-RHZG9UFC PUBLISHED CVSS 10 CRITICAL

A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP file upload interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability. This advisory is part of the May 2025 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: May 2025 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication ["https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75279"].

Risk Scores

CVSS v3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
17.12.1
17.12.3
17.11.1
17.13.1
17.14.1
17.12.2
17.11.99SW

Timeline

  • May 7, 2025 CVE Published
  • Jun 6, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›