CVE-2025-20218
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to retrieve sensitive information from an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to retrieve sensitive information from the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.45%
- CWE
- CWE-643
- Published
- 2025-08-14
- Last modified
- 2026-03-12
Affected products
- Cisco Cisco Firepower Management Center
- Cisco Cisco Firepower Management Center
- Cisco Cisco Firepower Management Center
- Cisco Cisco Firepower Management Center
- Cisco Cisco Firepower Management Center
- Cisco Cisco Firepower Management Center
- Cisco Cisco Firepower Management Center
- Cisco Cisco Firepower Management Center
Weakness type
Related vulnerabilities
- CVE-2026-9390 — XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
- CVE-2026-44962 — Plesk contains an XPath injection vulnerability in the APS Application Catalog search...
- CVE-2026-40699 — BIG-IP Configuration utility vulnerability
- CVE-2026-24343 — Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions
- CVE-2025-11844 — XPath Injection in Hugging Face Smolagents search_item_ctrl_f Function
- CVE-2022-43840 — IBM Aspera Console XPath injection
- CVE-2024-39565 — Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device.
- CVE-2024-2648 — Netentsec NS-ASG Application Security Gateway naccheck.php xpath injection