Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Why Android e-readers are better than Kindle Colorsoft (especially if you read comics)

    August 5, 2025

    Uzbekistan’s first unicorn, Uzum, jumps for $ 1.5B valuation

    August 5, 2025

    Trump Crypto Bibnings to order an inquiry: Report

    August 5, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Cisco maximum severity cures iOS XE defects kidnapped tools
    Security

    Cisco maximum severity cures iOS XE defects kidnapped tools

    PineapplesUpdateBy PineapplesUpdateMay 8, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Cisco maximum severity cures iOS XE defects kidnapped tools
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cisco maximum severity cures iOS XE defects kidnapped tools

    Cisco has fixed the maximum severity defect in the iOS XE software for wireless LAN controllers by a hard-coded JSON web token (JWT) that allows an informal remote attacker to handle equipment.

    This token is to certify requests for a feature called ‘out-of-band AP image download’. Since it is hard-coded, one can replicate an authorized user without credentials.

    The vulnerability has been tracked as the CVE-2025-20188 and has a maximum of 10.0 CVSS score, allowing the danger actors to fully compromise the equipment according to the seller.

    “An attacker can take advantage of this vulnerability by sending https requests prepared for AP image download interface,” Reads Cisco’s bulletin,

    “A successful exploitation may allow the attacker to upload files, travelers and execute arbitrary command with root privileges.”

    It is noted that the CVE-2025-20188 is only exploitative when the ‘out-of-band AP image download’ facility is capable on the device, which is not capable of default.

    The ‘out-of-band AP image download’ feature allows Access points (APS) to download OS images through HTTPS instead of Capawap Protocol, which is a more flexible and direct way to get firmware on APS.

    He said, although it is disabled by default, some large -scale or automatic enterprise deployment can enable it to provide a rapid provision or recovery of APS.

    The following equipment are insecure for the following equipment when meeting exploitation requirements:

    • Catalyst 9800-CL Wireless Controller for Cloud
    • Catalyst 9800 Cataly
    • Catalyst 9800 series wireless controller
    • Embedded wireless controller on catalyst AP

    On the other hand, products have been confirmed not to be affected by the hard-coded JWT issue: Cisco iOS (non-XE), Cisco iOS XR, Cisco Merki Products, Cisco NX-OS, and Cisco Ares-based WLC.

    Cisco has issued security updates to address important vulnerabilities, so system administrators are advised to implement them as soon as possible.

    Users can determine the exact version that fixes the defect for its device using Cisco software checkers for its specific device models.

    Although there are no mitigations or workarounds for the CVE-2025-20188, it is a solid defense to disable the ‘out-of-band AP image download’ feature.

    At this time, Cisco is unaware of any case of active exploitation for CVE-2015-20188. However, given the severity of the issue, the danger actors are likely to start scanning for weak closing points immediately.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    Cisco cures defects iOS kidnapped maximum severity Tools
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleI have used a Samsung the Frame TV for years, and here is why the frame pro is a huge upgrade
    Next Article IBM CEO: AI replaced hundreds of human resource employees
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Old office apps lose access to voice features in January

    August 5, 2025
    Security

    I found a small power bank that charge two devices at a time – for less than $ 25

    August 5, 2025
    Security

    Certain bug leaked in proton log fixes the totup secrets

    August 5, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Why Android e-readers are better than Kindle Colorsoft (especially if you read comics)

    August 5, 2025

    Uzbekistan’s first unicorn, Uzum, jumps for $ 1.5B valuation

    August 5, 2025

    Trump Crypto Bibnings to order an inquiry: Report

    August 5, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.