CVE-2025-20265: Critical Cisco FMC RCE Flaw via RADIUS – Patch Now
Monty4 min read
VULNERABILITY ANALYSIS#cisco#fmc#rce

CVE-2025-20265: Critical Cisco FMC RCE Flaw via RADIUS – Patch Now

Cisco discloses CVE-2025-20265, a critical RCE vulnerability in Secure Firewall Management Center (FMC) software. Flaw allows unauthenticated attackers to execute arbitrary commands with elevated privileges if RADIUS authentication is enabled.

Share:

A Perfect 10, and Not the Good Kind

On August 18, 2025, Cisco disclosed CVE-2025-20265, a critical remote code execution (RCE) vulnerability in the RADIUS subsystem of Cisco Secure Firewall Management Center (FMC) software.

It's rated CVSS 10.0 (Critical), and it lets unauthenticated remote attackers run arbitrary shell commands with elevated privileges on affected FMC systems.

Cisco is pushing immediate patching, especially for enterprises that use RADIUS authentication for FMC logins. When the thing being compromised is the box that manages your firewalls, the blast radius is your whole perimeter.


The Facts

Field Value
CVE ID CVE-2025-20265
CVSS Score 10.0 (Critical)
CWE CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component
Attack Vector Remote (unauthenticated)
Privileges Required None
Impact Arbitrary command execution with elevated privileges
Affected Products Cisco Secure FMC Software 7.0.7, 7.7.0 (with RADIUS authentication enabled)

What's Actually Broken

The vulnerability comes from improper input validation in the RADIUS authentication flow.

When Cisco FMC is set up to use RADIUS for management logins (via Web or SSH):

  • Maliciously crafted credentials can trigger command injection.
  • That lets a remote attacker run arbitrary shell commands as a privileged user.

I break into systems for a living, and this is about as clean as an exploit primitive gets. The injection lands in the login path, so the attacker never needs a valid account. The very mechanism meant to authenticate them becomes the way in. That's the same authentication-flow abuse we walked through in the Cisco IMC authentication bypass writeup.


Pulling It Off

Conditions for exploitation

  • ✅ Requires no prior authentication.
  • ✅ Only possible if RADIUS authentication is enabled in FMC.
  • ✅ The attacker sends crafted credentials during a login attempt (web or SSH).

What it leads to

If they succeed, attackers can:

  • Gain complete command execution with elevated privileges.
  • Disable firewall security controls.
  • Plant persistent backdoors or implants.
  • Pivot into internal corporate networks.

⚠️ Cisco has confirmed no active exploitation in the wild as of the disclosure date.

That "no exploitation yet" line never lasts long for a CVSS 10.0 on an internet-reachable management plane. We watched the same race play out with the Gladinet Triofox zero-day, where the window between disclosure and exploitation was measured in days.


What to Do About It

Apply the security updates

  • Cisco has released free software updates for CVE-2025-20265.
  • You should:
    • Use the Cisco Software Checker to verify exposure.
    • Identify the first fixed release that applies to you.
    • Deploy patches immediately.

Temporary mitigation

Cisco is clear that no complete workaround exists. That said, temporary mitigations include:

  • Disable RADIUS authentication on FMC.
  • Switch to an alternative authentication method:
    • Local FMC accounts
    • LDAP integration
    • SAML-based SSO

⚠️ Always test alternate authentication schemes before you roll them into production.

Tighten your posture

  • Restrict external exposure of FMC management interfaces.
  • Watch for unusual authentication attempts aimed at FMC.
  • Review logs for failed RADIUS login anomalies.

Here's the offensive-side reality though: once an attacker has RCE on the management plane, they own the audit trail too. Log review tells you what happened, not what's happening right now. That's where deception earns its keep. If you plant decoy admin credentials and credential mines around the management network, an attacker who lands on FMC and starts looking for the next hop trips an alert the moment they touch bait that no legitimate process ever should.


Bottom Line

CVE-2025-20265 is a critical CVSS 10.0 vulnerability that hands attackers total remote compromise of Cisco FMC systems whenever RADIUS authentication is enabled.

With an unauthenticated attack vector and the potential for full privilege execution, this is a top-priority patching event for every enterprise running Cisco Secure FMC.

Action required:

  • Apply Cisco's released updates immediately.
  • Disable RADIUS authentication where you can.
  • Enforce monitoring and keep FMC access restricted to trusted networks.

Patch first. Then ask yourself what would catch the intruder if the patch went out a day too late. See how Mine2's deception answers that.

M2

Monty

Offensive Security Lead, Mine2

Monty leads offensive security research at Mine2, breaking down how attackers turn vulnerabilities into footholds — and where deception trips them up first.

Share this article

Secure Your Network Today

Ready to implement advanced cyber deception in your organization? See how MINE2 can transform your threat detection capabilities.