CVE-2025-20149: Cisco IOS
Medium severity, CVSS 6.5. EPSS: 0.1% chance of exploitation in the next 30 days.
A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a buffer overflow. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the CLI prompt. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Affected products
- Cisco IOS: version 15.0(1)ex only; version 15.0(2)ea only; version 15.0(2)ea1 only; version 15.0(2)ej only; version 15.0(2)ej1 only; version 15.0(2)ek only; …
- Cisco IOS XE: version 3.2.0se only; version 3.2.1se only; version 3.2.2se only; version 3.2.3se only; version 3.3.0se only; version 3.3.0sg only; …
Published 2025-09-24. Last modified 2026-09-26.