OS Command Injection in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2025-20213
Published: May 9, 2025
Vulnerability details
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper access controls on files in the CLI. A local user can overwrite arbitrary files and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.