Vulnslist

find the latest Cisco vulnerabilities

CVE-2025-20216

A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This vulnerability is due to improper sanitization of input to the web interface. An attacker could exploit this vulnerability by convincing an authenticated user to click a malicious link. A successful exploit could allow the attacker to inject HTML into the browser of an authenticated Cisco Catalyst SD-WAN Manager user.

SeverityMEDIUM
CVSS4.7
CWECWE-74
KEV
Published
Modified

Related Products

Product Advisory Evidence
Cisco SD-WAN vManage cisco-sa-vmanage-html-inj-GxVtK6zj Cisco OpenVuln
Cisco Catalyst SD-WAN Manager cisco-sa-vmanage-html-inj-GxVtK6zj Cisco OpenVuln
Cisco Catalyst SD-WAN cisco-sa-vmanage-html-inj-GxVtK6zj Cisco OpenVuln