Vulnslist

find the latest Cisco vulnerabilities

Cisco Catalyst SD-WAN Manager Reflected HTML Injection Vulnerability

cisco-sa-vmanage-html-inj-GxVtK6zj · Medium · Published · Updated

A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This vulnerability is due to improper sanitization of input to the web interface. An attacker could exploit this vulnerability by convincing an authenticated user to click a malicious link. A successful exploit could allow the attacker to inject HTML into the browser of an authenticated Cisco Catalyst SD-WAN Manager user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-html-inj-GxVtK6zj

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2025-20216
Cisco Bug IDsCSCwk90639
CVSS ScoreBase 4.7
Base 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Catalyst SD-WAN Manager

Related Products

Product CVE Evidence
Cisco SD-WAN vManage CVE-2025-20216 Cisco OpenVuln
Cisco Catalyst SD-WAN Manager CVE-2025-20216 Cisco OpenVuln
Cisco Catalyst SD-WAN CVE-2025-20216 Cisco OpenVuln