CVE-2016-1363: Cisco Wireless Lan Controller Software

Critical severity, CVSS 9.8. EPSS: 5.6% chance of exploitation in the next 30 days.

Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through 8.0 before 8.0.115.0(ED) allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCus25617.

Affected products

  • Cisco Wireless Lan Controller Software: from 7.2.0, before 7.4.140.0 (fixed in 7.4.140.0); from 7.5.0, before 8.0.115.0 (fixed in 8.0.115.0)

Published 2016-04-21. Last modified 2026-06-17.