Thursday, September 17, 2026

Cisco IOS/XE Vulnerability Allows Unauthorized Access to Confidential Data

 Cisco released an advisory describing a high-severity vulnerability (CVE-2025-20160) in its IOS and IOS XE platforms. The flaw stems from improper validation of the TACACS+ shared secret configuration.

When TACACS+ is enabled but no secret is set, remote attackers or machine-in-the-middle adversaries can intercept or manipulate authentication messages.

Successful exploitation grants unauthorized access to confidential information or full device control.

Overview of the Vulnerability

The vulnerability exists because the software fails to verify that a TACACS+ shared secret has been configured before processing authentication requests.

An attacker on the network path can either read unencrypted TACACS+ messages or impersonate the TACACS+ server.

CVEAffected ProductsCVSS 3.1 Score
CVE-2025-20160Cisco IOS and IOS XE Software with TACACS+ configured without a shared secret8.1 (High)

By sending crafted responses, the attacker can bypass authentication checks altogether. This allows full administrative access to routers and switches running vulnerable IOS or IOS XE releases, exposing configuration data, credentials, and other sensitive information.

Any Cisco device running a vulnerable IOS or IOS XE release and configured for TACACS+ without a shared secret is at risk.

Impact ranges from unauthorized disclosure of TACACS+ payloads to complete authentication bypass, granting full administrative privileges.

Cisco has not observed any public exploits or malicious activity targeting this issue to date.

Cisco strongly urges all customers to apply the provided software updates immediately. Fixed releases are listed in the advisory’s “Fixed Software” section.

As a temporary measure, administrators must ensure every TACACS+ server configured on a device has a valid shared secret.

Use the show running-config | include tacacs server|key command to verify that no TACACS+ server entry is missing its key line.

After confirming proper key configuration, plan an upgrade to a fixed IOS or IOS XE version at the earliest opportunity.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation

A newly identified device-code phishing kit dubbed GhostCode exploits...

VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems

VectraRAT, a previously undocumented Malware-as-a-Service platform that combines remote-access...

TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password

Security researchers have revealed two vulnerabilities in TP-Link’s Tapo...

Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems

Chinese-speaking threat actors are continuing to rely on Noodle...

Axoflow Launches AxoDetect, Bringing Detection Into the Pipeline and Making the SIEM Optional

Stamford, CT, September 16th, 2026, CyberNewswire Now in early access,...

CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information

CenterPoint Energy has confirmed that an unauthorized third party...

Related Articles

Recent News