Cisco Secure Firewall Management Center RADIUS command injection (CVE-2025-20265)
Vulnerability
Summary
Hide ▲
Show ▼
Cisco has patched CVE-2025-20265, a CVSS 10.0 flaw in Secure Firewall Management Center (FMC) Software that can let an unauthenticated remote attacker execute arbitrary shell commands. The weakness affects the RADIUS subsystem when RADIUS authentication is enabled, putting FMC releases 7.0.7 and 7.7.0 at risk. Cisco said there is no workaround beyond applying the update. The issue was found during internal security testing, and Cisco said it was not actively exploited in the wild at disclosure.
Related Happenings
Cisco ASA and IOS/IOS XE zero-day exploitation wave
Exploitation Wave
First: 25.09.2025 22:22
Last: 25.09.2025 22:22
Sources 1
About this happening:
**Cisco** exploitation wave now includes **CVE-2025-20352** in **Cisco IOS Software** and **Cisco IOS XE**, where **Trend Micro** says **Operation Zero Disco** abused the **SNMP s...
Cisco ASA and IOS/IOS XE zero-day exploitation wave
Exploitation WaveAbout this happening: **Cisco** exploitation wave now includes **CVE-2025-20352** in **Cisco IOS Software** and **Cisco IOS XE**, where **Trend Micro** says **Operation Zero Disco** abused the **SNMP s...
Latest development: 16.10.2025 21:13
Trend Micro says attackers in Operation Zero Disco exploited CVE-2025-20352 in older Cisco IOS and IOS XE networking devices, including Cisco 9400, 9300, and legacy 3750G series devices, to deploy a Linux rootkit and gain persistent access; the activity also included attempts to abuse CVE-2017-3881 on Cisco switches lacking endpoint detection response solutions.
Cisco SNMP mitigation guidance for CVE-2025-20352
Advisory/Mitigation
First: 25.09.2025 09:30
Last: 25.09.2025 09:30
Sources 1
About this happening:
**Cisco** issued mitigation guidance for **CVE-2025-20352** on **SNMP-enabled IOS and IOS XE systems**, warning administrators to reduce exposure on devices that remain vulnerable...
Cisco SNMP mitigation guidance for CVE-2025-20352
Advisory/MitigationAbout this happening: **Cisco** issued mitigation guidance for **CVE-2025-20352** on **SNMP-enabled IOS and IOS XE systems**, warning administrators to reduce exposure on devices that remain vulnerable...
Timeline
-
15.08.2025 09:49 1 articles · 9mo ago
Cisco releases patches for CVE-2025-20265 in Secure Firewall Management Center
Mitigation Patch UpdateCisco released security updates for CVE-2025-20265, a CVSS 10.0 flaw in Secure Firewall Management Center (FMC) Software that can let an unauthenticated remote attacker inject arbitrary shell commands and execute code at a high privilege level. The issue stems from improper handling of user input during the authentication phase and affects RADIUS authentication in the web-based management interface, SSH management, or both, including Cisco Secure FMC Software releases 7.0.7 and 7.7.0 when RADIUS is enabled. Cisco said there is no workaround beyond applying the patches, credited Brandon Sakai of Cisco with finding the issue during internal security testing, and said none of the flaws were under active exploitation in the wild at disclosure.
Show sources
- Cisco Warns of CVSS 10.0 FMC RADIUS Flaw Allowing Remote Code Execution — thehackernews.com — 15.08.2025 09:49