CVE-2025-20190 Details
Description
A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to remove arbitrary users that are defined on an affected device. This vulnerability is due to insufficient access control of actions executed by lobby ambassador users. An attacker could exploit this vulnerability by logging in to an affected device with a lobby ambassador user account and sending crafted HTTP requests to the API. A successful exploit could allow the attacker to delete arbitrary user accounts on the device, including users with administrative privileges. Note: This vulnerability is exploitable only if the attacker obtains the credentials for a lobby ambassador account. This account is not configured by default.
A vulnerability exists in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software, allowing authenticated, remote attackers to delete arbitrary users from an affected device. This issue arises from inadequate access control for actions performed by lobby ambassador users. Exploitation requires logging in with a lobby ambassador account, which is not enabled by default, and sending crafted HTTP requests to the API. Successful exploitation could result in the deletion of user accounts, including those with administrative rights.
Cisco has released software updates to address this vulnerability. Instructions for upgrading can be found on the Cisco Security Advisories page. To determine exposure to this vulnerability, users can consult the Cisco Software Checker tool.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ewlc-user-del-hQxMpUDj | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco ios xe | 17.6.8 17.9.6 17.9.6a 17.12.1z2 17.12.1z3 17.15.1 17.15.1x |
CPE
Remediation
| |
| cisco catalyst 9800-cl wireless controllers for cloud | All versions |
CPE
Remediation
| |
| cisco catalyst 9105axi | All versions |
CPE
Remediation
| |
| cisco catalyst 9115axe | All versions |
CPE
Remediation
| |
| cisco catalyst 9115axi | All versions |
CPE
Remediation
| |
| cisco catalyst 9117axi | All versions |
CPE
Remediation
| |
| cisco catalyst 9120axe | All versions |
CPE
Remediation
| |
| cisco catalyst 9120axi | All versions |
CPE
Remediation
| |
| cisco catalyst 9120axp | All versions |
CPE
Remediation
| |
| cisco catalyst 9130axe | All versions |
CPE
Remediation
| |
| cisco catalyst 9130axi | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-40 | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-80 | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-l | All versions |
CPE
Remediation
| |
| cisco catalyst cw9800h1 | All versions |
CPE
Remediation
| |
| cisco catalyst cw9800h2 | All versions |
CPE
Remediation
| |
| cisco catalyst cw9800m | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | Initial Analysis | [email protected] |
| May 7, 2025 | New CVE Received | [email protected] |