PT-2025-20278 · Cisco · Cisco Catalyst Sd-Wan Manager

Published

2025-05-07

·

Updated

2025-07-29

·

CVE-2025-20216

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Catalyst SD-WAN Manager (affected versions not specified)
Description A vulnerability in the web interface could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This issue is due to improper sanitization of input to the web interface. An attacker could exploit this by convincing an authenticated user to click a malicious link, potentially allowing the attacker to inject HTML into the browser of an authenticated Cisco Catalyst SD-WAN Manager user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-20216

Affected Products

Cisco Catalyst Sd-Wan Manager