Reflected Cross-Site Scripting Vulnerability in Cisco IOS XE Software
CVE-2025-20240
What is CVE-2025-20240?
A vulnerability in the web user interface of Cisco IOS XE Software allows unauthenticated remote attackers to exploit insufficient sanitization of user input. By tricking users into clicking a crafted link, an attacker can execute a reflected cross-site scripting (XSS) attack. This could enable the attacker to gain unauthorized access to cookies stored in the user’s session on the targeted device, thereby compromising security and allowing further malicious actions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco IOS XE Software 16.6.1
Cisco IOS XE Software 16.6.2
Cisco IOS XE Software 16.6.3
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved