CVE-2025-20148 is a high-severity vulnerability affecting Cisco Secure Firewall Management Center (FMC) Software, allowing an authenticated, remote attacker to inject arbitrary HTML into device-generated documents. This flaw, stemming from improper user input validation, enables attackers with at least Security Analyst (Read Only) credentials to alter document layouts, read arbitrary files, and conduct Server-Side Request Forgery (SSRF) attacks. With a CVSS score of 8.5, the attack is network-based and low complexity, requiring only valid user credentials. While not currently listed in CISA's KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, indicating potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.6CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6:*:*:*:*:*:*:* | ||
7.0.6.1CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.1:*:*:*:*:*:*:* | ||
7.0.6.2CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.2:*:*:*:*:*:*:* | ||
7.0.6.3CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.3:*:*:*:*:*:*:* | ||
7.2.4CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:7.2.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.