CVE-2025-20281
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.
- Affected products
- Cisco Ise, Cisco Ise-Pic
- Cisco Identity Services Engine
- = 3.3.0, 3.4.0
- Cisco Identity Services Engine Passive Identity Connector
- = 3.3.0, 3.4.0
- Fix
- Available
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 97.1% (100th percentile)
- Weakness
- CWE-74
- NVD status
- Analyzed
- Published
- 2025-06-25
CVE-2025-20281 at NVD
13 known exploits for CVE-2025-20281
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2025-20281-Cisco
Cisco-CVE-2025-20281-illdeed
CVE-2025-20281-2-Cisco-ISE-RCE
CVE-2026-20180
Exploit for CVE-2026-20180
π Cisco ISE API 3.2 Command Injection
π Cisco ISE API 3.1 Command Injection
π Cisco ISE API 3.0 Command Injection
Exploit for Injection in Cisco Identity_Services_Engine
Exploit for Injection in Cisco Identity_Services_Engine
Exploit for Injection in Cisco Identity_Services_Engine
Exploit for Injection in Cisco Identity_Services_Engine
Exploit for Injection in Cisco Identity_Services_Engine