PT-2025-39297 · Cisco · Cisco Ios Xe

Published

2025-09-24

·

Updated

2025-09-25

·

CVE-2025-20240

CVSS v3.1
6.1
VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

**Name of the Vulnerable Software and Affected Versions**

Cisco IOS XE Software (affected versions not specified)

**Description**

A flaw exists in the web UI of Cisco IOS XE Software that could permit an unauthenticated, remote attacker to perform a reflected cross-site scripting (XSS) attack on a vulnerable device. This issue stems from insufficient sanitization of user-provided input. An attacker could potentially exploit this by tricking a user into clicking a malicious link, which could lead to the execution of a reflected XSS attack and the theft of user cookies from the affected device.

**Recommendations**

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-20240

Affected Products

Cisco Ios Xe