Cisco Security Advisory
Follow
Cisco Secure Firewall Management Center Software HTML Injection Vulnerability
A vulnerability exists in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw allows an authenticated, remote attacker to inject arbitrary HTML content into documents generated by the device. The vulnerability stems from improper validation of user-supplied data within the interface. An attacker with at least Security Analyst (Read Only) privileges can exploit this by submitting malicious content. Successful exploitation can alter document layouts, read arbitrary files from the operating system, and perform server-side request forgery (SSRF) attacks. Cisco has released software updates to fix this vulnerability. Currently, there are no available workarounds to mitigate this issue. The security impact of this vulnerability is rated as High. This vulnerability is identified as CVE-2025-20148. Further details can be found in the Cisco Security Advisory linked in the original text.