Urgent Security Advisory: CVE-2025-20265 – Critical RCE Vulnerability (CVSS 10.0) in Cisco Secure FMC
Cisco has released a critical security update addressing an unauthenticated remote code execution (RCE) vulnerability-CVE-2025-20265-in its Secure Firewall Management Center (FMC) Software. With the maximum CVSS score of 10.0, this flaw demands immediate attention from network defenders. What's the Threat? This vulnerability resides in the RADIUS subsystem of Cisco Secure FMC, specifically affecting versions 7.0.7 and 7.7.0 when RADIUS authentication is enabled for either the web-based management interface or SSH access. Due to improper input handling during authentication, attackers can inject shell commands via crafted credentials, executed with high privilege on the target system. Why It's Alarming Maximum Severity (CVSS 10.0): Indicates easy exploitability with catastrophic impact. No Privileges Required: The attack requires no prior authentication or user interaction. High Impact on Availability & Integrity: If exploited, attackers gain full control over firewall management. No Workarounds Available: Only timely patching will eliminate this threat. No Known Exploits Yet: Cisco currently…