Access Control Flaw in Cisco IOS XE Wireless Controller Software
CVE-2025-20190

6.5MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
7 May 2025

Badges

👾 Exploit Exists

Summary

A significant security flaw exists in the lobby ambassador web interface of Cisco's IOS XE Wireless Controller Software. This vulnerability allows authenticated remote attackers to delete arbitrary user accounts, including those with administrative privileges. The issue arises from inadequate access control over actions performed by lobby ambassador users. Exploitation requires the attacker to log in using a lobby ambassador account and issue specially crafted HTTP requests to the API. Since lobby ambassador accounts are not configured by default, an attacker must first obtain the credentials for such an account to execute the exploit.

Affected Version(s)

Cisco IOS XE Software 17.6.8

Cisco IOS XE Software 17.9.6

Cisco IOS XE Software 17.9.6a

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20190 : Access Control Flaw in Cisco IOS XE Wireless Controller Software | SecurityVulnerability.io