Improper Verification of Cryptographic Signature in Cisco Systems, Inc products - CVE-2025-20248
Published: September 11, 2025
Vulnerability identifier: #VU115156
CSH Severity:
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20248
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to incomplete validation of files during the installation of an .iso file. A local administrator can load an unsigned file as part of the image activation process.
Affected software
IOS XR White box
NCS 1000 Series
NCS 6000 Series Routers
NCS 5700 Series Routers
NCS 5000
Cisco Network Convergence System 540 Series Routers
Cisco IOS XRv 9000 Router
Cisco ASR 9000 Series Aggregation Services Routers
NCS5500
NCS560
Cisco IOS XR
NCS 1000 Series
NCS 6000 Series Routers
NCS 5700 Series Routers
NCS 5000
Cisco Network Convergence System 540 Series Routers
Cisco IOS XRv 9000 Router
Cisco ASR 9000 Series Aggregation Services Routers
NCS5500
NCS560
Cisco IOS XR
How to mitigate CVE-2025-20248
Install updates from vendor's website.
Cisco IOS XR - addressed in versions 24.2.21, 24.3.20, 24.3.30, 24.4.2, 24.4.30, 25.1.1, 25.1.2, 25.2.1