OS Command Injection in Cisco DNA Center (Catalyst Center) - CVE-2025-20349

 

OS Command Injection in Cisco DNA Center (Catalyst Center) - CVE-2025-20349

Published: November 13, 2025


Vulnerability identifier: #VU118523
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20349
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to improper input validation in REST API request parameters. A remote authenticated user can pass specially crafted request to the affected API endpoint and execute arbitrary OS commands as root. 


Affected software

Cisco DNA Center (Catalyst Center)

How to mitigate CVE-2025-20349

Install updates from vendor's website.

Cisco DNA Center (Catalyst Center) - update to 2.3.7.10

External References

Related Security Bulletins