Path traversal in Cisco Systems, Inc products - CVE-2025-20314

 

Path traversal in Cisco Systems, Inc products - CVE-2025-20314

Published: September 25, 2025


Vulnerability identifier: #VU116110
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20314
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform directory traversal attacks.

The vulnerability exists due improper validation of software packages. A local adinistrator can send a specially crafted HTTP request and upload arbitrary files on the system, leading to arbitrary commands execution.


Affected software

4000 Series Integrated Services Routers
1100 Terminal Services Gateways
Catalyst IR8300 Rugged Series Routers
1000 Series Integrated Services Routers
Catalyst 8200 Series Edge Platforms
Catalyst 8300 Series Edge Platforms
Catalyst 8500L Edge Platforms
Catalyst 9200 Series Switches
8400 Series Secure Routers
Catalyst IE3300 Rugged Series Routers
Embedded Services 3300 Series
8100 Series Secure Routers
C8375-E-G2 Platforms
VG410 Analog Voice Gateways
ASR 1000 Series Aggregation Services Routers
Catalyst IR8100 Heavy Duty Series Routers
Catalyst IR1100 Rugged Series Routers
Cisco IOS XE

How to mitigate CVE-2025-20314

Install updates from vendor's website.

Cisco IOS XE - addressed in versions Cupertino-17.9.8, 17.9.8, 17.12.6, 17.12.6a, 17.15.1z, 17.15.4, 17.15.4a, 17.15.4b, 17.18.1, 17.18.1a
ASR 1000 Series Aggregation Services Routers - update to 17.7.1

External References

Related Security Bulletins