Vulnerability in Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers
CVE-2025-20293
What is CVE-2025-20293?
A vulnerability in the initial Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers could permit an unauthenticated, remote attacker to access the public-key infrastructure server on affected devices. This issue arises due to insufficient cleanup after the Day One setup, allowing attackers to send Simple Certificate Enrollment Protocol requests. An exploit could enable attackers to acquire a certificate from the virtual wireless controller, facilitating the unauthorized joining of malicious devices to the controller.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco IOS XE Software 16.10.1
Cisco IOS XE Software 16.10.1s
Cisco IOS XE Software 16.10.1e
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved