CVE-2025-20155
MEDIUMDescription
A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient input validation of the bootstrap file that is read by the system software when a device is first deployed in SD-WAN mode or when an administrator configures SD-Routing on the device. An attacker could exploit this vulnerability by modifying a bootstrap file generated by Cisco Catalyst SD-WAN Manager, loading it into the device flash, and then either reloading the device in a green field deployment in SD-WAN mode or configuring the device with SD-Routing. A successful exploit could allow the attacker to perform arbitrary file writes to the underlying operating system.
Is your site exposed to CVE-2025-20155?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
References
Frequently Asked Questions
What is CVE-2025-20155? +
How severe is CVE-2025-20155? +
What products are affected by CVE-2025-20155? +
How do I check if I'm vulnerable to CVE-2025-20155? +
Related Vulnerabilities
A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated …
Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection. A bad actor …
A security issue exists due to improper handling of CIP Class 32’s request when a module is inhibited on the …
A security issue exists due to improper handling of CIP Class 32’s request when a module is inhibited on the …
Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in …
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows …