Cisco has patched a worrying error that could have let attackers hijacked units


  • Cisco has patched a 10/10 error in iOS XE Software for wireless LAN CONTROLLERS
  • The error was due to hard -coded tokens
  • There is no evidence of abuse in nature (yet)

Cisco has released a patch for an error in maximum severity found in its iOS XE software for wireless LAN controllers that could have enabled threat players to take over vulnerable end points.

The error is another case of hard -coded credentials, this time in the form of a JSON -web -Token (JWT). “An striker could take advantage of this vulnerability by sending designed HTTPS requests to the AP image transfer interface,” it is explained on the NVD website. “Successful exploitation could allow the striker to upload files, perform the path review and perform arbitrary commands with root privileges.”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top