S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Aug 4, 2026

CVE-2025-20282 Scanner

CVE-2025-20282 Scanner - Unrestricted File Upload vulnerability in Cisco Identity Services Engine

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-20282
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Cisco Identity Services Engine Softwareby Cisco
3.4.0
Updated Aug 5, 2026View on NVD →
Detail

Cisco Identity Services Engine (ISE) is widely used in corporate environments for network access control, providing secure access to corporate networks. ISE automates network enforcement for security policies across a distributed network. The platform is utilized by network administrators to enforce security policies, provide visibility, and manage compliance across wired, wireless, and VPN networks. Key functionalities include guest access, secure network access, contextual understanding, and visibility into who and what is part of the network landscape. Organizations deploy Cisco ISE to ensure that only trusted devices gain access to network resources, enhancing both security and compliance.

The unrestricted file upload vulnerability in Cisco Identity Services Engine (ISE) enables attackers to bypass security controls by uploading files without proper validation. This issue is caused by inadequate file validation in an internal API, allowing unauthenticated attackers to upload files that can be executed by the system, potentially as root. Attackers can exploit this flaw to execute arbitrary code on the server, effectively compromising the system. The vulnerability is particularly dangerous because it does not require authentication and can lead to complete control over affected systems.

The technical details of this vulnerability involve exploiting an internal API endpoint in Cisco ISE that fails to enforce proper file validation rules, allowing unauthenticated parties to upload files. The vulnerability is triggered by submitting a crafted ZIP file through a POST request to the "/admin/files-upload/" endpoint. Once the file is uploaded, due to improper checks, it can be executed in the server's context. Successful exploitation results in the execution of arbitrary code, such as a crafted shell script or executable, effectively giving attackers elevated privileges on the system.

When this vulnerability is exploited by malicious actors, it can lead to severe consequences, including unauthorized access to sensitive data and potentially full control over the system. Attackers may use this to escalate privileges, install malware, vandalize the server, or access data stored within the corporate network. These actions could cause significant operational disruptions, data breaches, and loss of user trust for the organization.

REFERENCES

Solution Advice
  • Update Cisco ISE to version 3.4P2 or later, including all recent security patches.
  • Implement strict file validation checks within internal APIs to prevent unauthorized uploads.
  • Regularly audit and monitor system logs for unusual or unauthorized activity.
  • Restrict network access to the ISE management interfaces.
  • Educate staff on security best practices and potential signs of unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.