CVE-2025-20179
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-20179 is a newly identified vulnerability affecting the web-based management interface of Cisco Expressway Series devices. This issue allows unauthenticated, remote attackers to execute cross-site scripting (XSS) attacks on users of the interface. The vulnerability stems from the interface's failure to adequately validate user-supplied input. An adversary could manipulate a user into clicking a malicious link, resulting in the execution of arbitrary script code in the context of the affected interface or the unauthorized access of sensitive data. Cisco Expressway Series includes both Expressway Control (Expressway-C) and Expressway Edge (Expressway-E) devices.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.