Remote Command Execution Vulnerability in Cisco Catalyst Center REST API
CVE-2025-20349
What is CVE-2025-20349?
A vulnerability exists within the REST API of Cisco Catalyst Center, allowing an authenticated remote attacker to execute arbitrary commands with root privileges in a restricted container. This exploit emerges from inadequate validation of user-supplied input in API request parameters. An attacker with valid credentials, possessing at least Observer role access, can leverage this flaw by sending specially crafted API requests, potentially leading to unauthorized command execution that can compromise the integrity of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Digital Network Architecture Center (DNA Center) 1.4.0.0
Cisco Digital Network Architecture Center (DNA Center) 2.1.1.0
Cisco Digital Network Architecture Center (DNA Center) 2.1.1.3
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved