Severe Flaw in Cisco Wireless Controllers Opens Door to Full Device Takeover
Cisco has issued an urgent alert about a newly uncovered critical security flaw in its IOS XE Wireless LAN Controllers (WLCs), which could hand complete control of vulnerable systems to remote attackers—without any need for login credentials.
Assigned the highest possible CVSS score of 10.0, the flaw empowers unauthenticated users to remotely upload rogue files, navigate through system directories, and run commands with unrestricted root access.
Cataloged as CVE-2025-20188, the flaw originates from the Out-of-Band Access Point (AP) Image Download component in certain versions of IOS XE used by Cisco WLCs. The vulnerability is linked to the presence of a hard-coded JSON Web Token (JWT)—a serious oversight that opens a direct path for malicious access.
By issuing carefully crafted HTTPS requests to the affected interface, attackers can exploit this weakness to drop arbitrary files anywhere on the system and execute them with full privileges.
“This bug presents a clear and present danger to corporate wireless infrastructures,” noted one cybersecurity researcher. “With no authentication hurdles and root-level access, attackers can effectively hijack the entire device.”
Products at Risk:
This vulnerability impacts Cisco WLCs with the vulnerable AP image download feature enabled, specifically:
- Catalyst 9800-CL Wireless Controllers for Cloud
- Catalyst 9800 Embedded Controllers for Catalyst 9300/9400/9500 Switches
- Catalyst 9800 Series Wireless Controllers
- Embedded Wireless Controller on Catalyst Access Points
Network administrators can check exposure using the command:show running-config | include ap upgrade
If the response includes ap upgrade method https, the system is vulnerable.
No Workarounds – Immediate Action Required
Cisco has released patches to neutralize the issue, strongly advising customers to update immediately. There are no official workarounds. However, disabling the vulnerable AP image download feature can offer short-term protection.
Security teams are urged to act quickly, especially in environments where the update cannot be deployed right away.
The issue was identified by X.B. of the Cisco Advanced Security Initiatives Group during routine internal security testing. As of now, there are no signs of this vulnerability being exploited in the wild.
This disclosure is part of Cisco’s May 2025 IOS and IOS XE Software Security Advisory bundle, which also addresses other critical flaws across its product ecosystem.




