Citrix cybersecurity
– urzine/Getty Images

Cisco users are urgently advised to update their firewall command center in light of a remote code execution (RCE) vulnerability.

According to a "critical"-level alert issued last week, Cisco’s Secure Firewall Management Center (FMC) product is under threat from a flaw that allows a bad actor to “inject arbitrary shell commands that are executed by the device.”

Tracked as CVE-2025-20265, the vulnerability affects Cisco Secure FMC in remote authentication dial-in user service (RADIUS) subsystem mode. This system is used to validate, grant privileges, and monitor usage for firewall administrators and VPN users by connecting to an external authentication server.

The flaw affects Cisco Secure FMC Software releases 7.0.7 and 7.7.0, with the bug exploitable if the software is configured for RADIUS authentication for the web-based management interface, SSH management, or both.

“An attacker could exploit this vulnerability by sending crafted input when entering credentials that will be authenticated at the configured RADIUS server. A successful exploit could allow the attacker to execute commands at a high privilege level,” Cisco warned.

The security giant has advised users to switch to another type of authentication, such as local user accounts, external LDAP authentication, or SAML single sign-on (SSO). It has also provided software updates that address the vulnerability, with users advised to act immediately.

No in-the-wild exploits have yet been detected regarding the Secure FMC bug. The platform is commonly used by enterprise and government networks, suggesting a potentially large attack surface.

The flaw follows recent Cisco issues affecting its IP telephony systems, and a similar RCE exploit revealed in June.

RCE issues have also affected Microsoft systems recently, with one exploit this week taking down telecom vendor Colt platforms, an issue which remains ongoing at time of writing.