Serial number:AV25-616
Date:September 24, 2025
Updated:October 17, 2025
On September 24, 2025, Cisco published security advisories to address vulnerabilities in the following products:
- Cisco Access Point Software – multiple versions and platforms
- Cisco Catalyst 9500X and 9600X Series Switches – multiple versions
- Cisco IOS XE Software for Catalyst 9XXX Series Switches – multiple versions and platforms
- Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud – multiple versions and platforms
- Cisco IOS and IOS XE Software – multiple versions and platforms
- Cisco Industrial Ethernet (IE) Series Switches – multiple versions and platforms
- Cisco SD-WAN vEdge Routers – multiple versions and platforms
- Cisco SD-WAN vEdge Software Release – versions prior to 20.8, 20.9 and 20.10
- Cisco Wireless Access Point (AP) Software – multiple versions and platforms
- Cisco Wireless LAN Controller (WLC) IOS XE Software – multiple versions and platforms
Update 1
On September 29, 2024, CISA released a statement indicating that CVE-2025-20352 is being actively exploited in the wild and added it to their Known Exploited Vulnerabilities (KEV) Catalog.
The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.