Access Control Flaw in Cisco IOS XE Wireless Controller Software
CVE-2025-20190
Summary
A significant security flaw exists in the lobby ambassador web interface of Cisco's IOS XE Wireless Controller Software. This vulnerability allows authenticated remote attackers to delete arbitrary user accounts, including those with administrative privileges. The issue arises from inadequate access control over actions performed by lobby ambassador users. Exploitation requires the attacker to log in using a lobby ambassador account and issue specially crafted HTTP requests to the API. Since lobby ambassador accounts are not configured by default, an attacker must first obtain the credentials for such an account to execute the exploit.
Affected Version(s)
Cisco IOS XE Software 17.6.8
Cisco IOS XE Software 17.9.6
Cisco IOS XE Software 17.9.6a
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved