Tech

Cisco has patched a worrying flaw which could have let attackers hijack devices

Share
Share


  • Cisco has patched a 10/10 flaw in IOS XE Software for Wireless LAN Controllers
  • The flaw was due to hardcoded tokens
  • There is no evidence of abuse in the wild (yet)

Cisco has released a patch for a maximum-severity flaw found in its IOS XE Software for Wireless LAN Controllers which could have allowed threat actors to take over vulnerable endpoints.

The flaw is yet another case of hardcoded credentials, this time in the form of a JSON Web Token (JWT). “An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP image download interface,” it is explained in the NVD website. “A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.”

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
AI is making phishing emails dangerously convincing with better spelling, grammar and formatting
Tech

AI is making phishing emails dangerously convincing with better spelling, grammar and formatting

Experts warn AI-written phishing emails look polished and bypass traditional email filters...

AI-driven layoffs accelerate as companies push humans aside in favor of automation
Tech

AI-driven layoffs accelerate as companies push humans aside in favor of automation

AI threatens jobs across sectors from routine work to skilled professions CrowdStrike...