
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20265 is a critical OS command injection vulnerability in the RADIUS subsystem of Cisco Secure Firewall Management Center (FMC) Software that allows an unauthenticated, remote attacker to execute arbitrary shell commands at a high privilege level. It was discovered internally by Cisco security researcher Brandon Sakai and publicly disclosed on August 14, 2025. The vulnerability affects only Cisco Secure FMC Software releases 7.0.7 and 7.7.0 when RADIUS authentication is enabled for the web-based management interface, SSH management, or both. Cisco ASA and FTD software are not affected. It carries a CVSS v3.1 base score of 10.0 (Critical) (Cisco Advisory, BleepingComputer).
The root cause is classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — Injection), with an estimated CWE-78 (OS Command Injection) characterization. The vulnerability arises from a lack of proper input sanitization during the RADIUS authentication phase: when a user submits credentials to be validated against a configured RADIUS server, the FMC software fails to neutralize special shell metacharacters in the input before passing it to an OS-level command context. An attacker can exploit this by sending crafted credential input (e.g., embedding shell command sequences) to the FMC web management interface or SSH login prompt, triggering command execution without any prior authentication. Exploitation requires only that RADIUS authentication be enabled on the target FMC instance — no credentials or user interaction are needed (Cisco Advisory, ZeroPath).
Successful exploitation grants an unauthenticated remote attacker the ability to execute arbitrary shell commands at a high privilege level on the Cisco Secure FMC device, resulting in complete compromise of the firewall management platform. This enables an attacker to modify security policies, access sensitive configuration data and credentials, disable or alter firewall rules, and disrupt firewall operations — effectively undermining the security posture of all managed Cisco Secure Firewall devices. The changed scope (S:C) in the CVSS vector reflects that a compromised FMC can cascade to impact all downstream firewalls it manages, enabling significant lateral movement across enterprise networks (Cisco Advisory, The Register).
;, |, $(...), or backticks) within the username or password field that will be passed unsanitized to the underlying OS command context during RADIUS authentication processing.$(...)) in username or password fields; RADIUS authentication failures or unexpected successes from unknown source IPs; system logs showing command execution events not initiated by legitimate administrators./bin/sh, bash, curl, wget, python, nc); unusual processes running as root or high-privilege accounts not associated with normal FMC operations.Cisco has released free software updates that address this vulnerability; customers should upgrade affected FMC instances (versions 7.0.7 and 7.7.0) to the fixed releases identified in the Cisco Software Checker on the advisory page (Cisco Advisory). There are no direct workarounds that fully address the vulnerability; however, Cisco notes that the flaw can only be exploited if RADIUS authentication is configured. As a temporary mitigation, organizations can disable RADIUS authentication and switch to an alternative method such as local user accounts, external LDAP authentication, or SAML single sign-on (SSO). Additionally, restricting network-level access to the FMC management interface (web and SSH) to trusted IP ranges via ACLs or firewall rules will significantly reduce exposure. Customers should verify the applicability and impact of any mitigation in their own environment before deployment (Cisco Advisory, BleepingComputer).
The vulnerability received widespread coverage across the security community given its maximum CVSS 10.0 score. The Hacker News, BleepingComputer, The Register, Security Affairs, Infosecurity Magazine, ZDNet, CyberScoop, and SecurityWeek all published coverage within 24–48 hours of disclosure (BleepingComputer, The Register). The Register noted that this is part of a pattern of "perfect 10" severity bugs in Cisco products during summer 2025, and highlighted the risk of nation-state actors — particularly Chinese threat groups — targeting Cisco networking devices. Government CERTs including Ireland's NCSC, Australia's WA SOC, Singapore's CSA, and Belgium's CCB issued advisories urging immediate patching. The CIS also published an advisory noting the vulnerability could allow arbitrary code execution. Community discussion on Reddit's r/CVEWatch ranked it among the top trending CVEs for multiple consecutive days following disclosure (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."