Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Uzbekistan’s Uzum valuation leaps over 50% in seven months to $2.3B

    March 10, 2026

    Yann LeCun’s AMI Labs raises $1.03 billion to build world models

    March 10, 2026

    Bluesky CEO Jay Graber steps down

    March 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Uzbekistan’s Uzum valuation leaps over 50% in seven months to $2.3B
    • Yann LeCun’s AMI Labs raises $1.03 billion to build world models
    • Bluesky CEO Jay Graber steps down
    • Periwinkle is making self-hosted social media on Bluesky’s AT Protocol even easier
    • Palmer Luckey’s retro gaming startup ModRetro reportedly seeks funding at $1B valuation
    • Robinhood’s startup fund stumbles in NYSE debut
    • City Detect, which uses AI to help cities stay safe and clean, raises $13M Series A
    • Cluely CEO Roy Lee admits to publicly lying about revenue numbers last year
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»Cisco Wireless LAN Controllers under threat again after critical exploit details go public
    Security

    Cisco Wireless LAN Controllers under threat again after critical exploit details go public

    TechurzBy TechurzJune 3, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Cisco building exterior with sign
    Share
    Facebook Twitter LinkedIn Pinterest Email


    According to the Horizon3 analysis, a hard-coded JSON Web Token (JWT) is at the root of the exploit. “It’s crucial to eliminate hard-coded secrets from authentication workflows, enforce robust file upload validation and path sanitization, and maintain continuous monitoring and patch management across all critical systems,” Barne added.

    Diffing allowed locating hard-coded JWT

    Tracked as CVE-2025-20188, the flaw disclosed earlier in May was revealed to be an issue affecting the Out-of-Band Access Point (AP) Download feature of Cisco IOS XE Software for WLCs. The AP image download interface uses a hard-coded JWT for authentication, which an attacker can use to authenticate requests without valid credentials.

    Horizon3 researchers diffed file system contents from ISO images to arrive at the Lua scripts, where notable changes were found. The scripts referenced both JWT tokens and the associated key, indicating their involvement in the vulnerability. The researchers then performed a simple grep search across the source code to determine how and where these Lua scripts were invoked.

    Cisco controllers Critical details exploit LAN Public threat wireless
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThis MacBook Air price cut at Amazon is the laptop deal of the year so far
    Next Article NiCE launches new branding as it shifts from CCaaS to CX-focused AI platform
    Techurz
    • Website

    Related Posts

    Opinion

    Self-driving truck startup Einride raises $113M PIPE ahead of public debut

    February 26, 2026
    Opinion

    ‘Clueless’ -inspired app Alta partners with brand Public School to start integrating styling tools into websites

    February 14, 2026
    Opinion

    SpaceX is coming to the public markets, and secondaries are already on fire

    January 28, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,286 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,286 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Our Picks

    Uzbekistan’s Uzum valuation leaps over 50% in seven months to $2.3B

    March 10, 2026

    Yann LeCun’s AMI Labs raises $1.03 billion to build world models

    March 10, 2026

    Bluesky CEO Jay Graber steps down

    March 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.