Cisco Security Advisory
Follow
Cisco Secure Firewall Management Center Software Command Injection Vulnerability
A vulnerability exists in the web-based management interface of Cisco Secure Firewall Management Center Software. This flaw allows an authenticated remote attacker with Administrator privileges to run arbitrary commands. The vulnerability stems from inadequate input validation of specific HTTP request parameters. An attacker can exploit this by logging into the interface and sending a specially crafted HTTP request. A successful exploit would grant the attacker the ability to execute commands as the root user. Crucially, the attacker needs Administrator-level credentials to leverage this vulnerability. Cisco has released software updates to resolve this issue. Unfortunately, there are no workarounds available to mitigate this specific vulnerability. The security impact rating for this vulnerability is classified as Medium. This vulnerability is identified by CVE-2025-20306 and is part of a larger security advisory bundle from Cisco.