Reflected Cross-Site Scripting Vulnerability in Cisco IOS XE Software
CVE-2025-20240

6.1MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
24 September 2025

Badges

👾 Exploit Exists

What is CVE-2025-20240?

A vulnerability in the web user interface of Cisco IOS XE Software allows unauthenticated remote attackers to exploit insufficient sanitization of user input. By tricking users into clicking a crafted link, an attacker can execute a reflected cross-site scripting (XSS) attack. This could enable the attacker to gain unauthorized access to cookies stored in the user’s session on the targeted device, thereby compromising security and allowing further malicious actions.

Affected Version(s)

Cisco IOS XE Software 16.6.1

Cisco IOS XE Software 16.6.2

Cisco IOS XE Software 16.6.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20240 : Reflected Cross-Site Scripting Vulnerability in Cisco IOS XE Software