CVE-2025-20221: Cisco IOS XE
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. This vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by sending a crafted packet to the affected device. A successful exploit could allow the attacker to bypass the Layer 3 and Layer 4 traffic filters and inject a crafted packet into the network.
Affected products
- Cisco IOS XE: version 16.12.13 only; version 17.1.1 only; version 17.1.1s only; version 17.1.1t only; version 17.1.3 only; version 17.2.1 only; …
Published 2025-05-07. Last modified 2026-06-17.