OS Command Injection in Cisco DNA Center (Catalyst Center) - CVE-2025-20349
Published: November 13, 2025
Vulnerability identifier: #VU118523
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20349
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to improper input validation in REST API request parameters. A remote authenticated user can pass specially crafted request to the affected API endpoint and execute arbitrary OS commands as root.
Affected software
Cisco DNA Center (Catalyst Center)
How to mitigate CVE-2025-20349
Install updates from vendor's website.
Cisco DNA Center (Catalyst Center) - update to 2.3.7.10