CVE-2025-20281

Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

CVE-2025-20281 is a remote code execution vulnerability affecting Cisco Identity Services Engine (ISE). The vulnerability allows an unauthenticated, remote attacker to execute arbitrary code on the remote host as the root user due to insufficient validation of user-supplied input.

Exploiting this vulnerability can allow an attacker to gain complete control over the affected system. This includes accessing sensitive data, modifying or deleting system resources, and potentially installing malware or creating backdoors.

Mitigations

  • Apply the relevant patches as mentioned in the vendor advisory.

Rapid Response N-Day Testing

References

🔗 CVE-2025-20281 

🔗 Cisco Advisory 

🔗 The Hacker News Article 

Read about other CVEs

CVE-2024-23108

Fortinet FortiSIEM 2nd Order Command Injection

Read More

CVE-2023-43208

NextGen Mirth Connect Pre-Auth RCE

Read More

CVE-2023-34992

Fortinet FortiSIEM Command Injection

Read More

NodeZero® Platform

Implement a continuous find, fix, and verify loop with NodeZero

The NodeZero® platform empowers your organization to reduce your security risks by autonomously finding exploitable weaknesses in your network, giving you detailed guidance around how to priortize and fix them, and having you immediately verify that your fixes are effective.
Explore NodeZero

Recognized By