CVE-2025-20282

CRITICAL EXPLOITED

Cisco Identity Services Engine and ISE-PIC - Unauthenticated Arbitrary File Upload and Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-20282 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 7 public exploits from researchers including adminlove520, skadevare, pairofglasses.

AI-analyzed exploit summary This repository contains functional exploit code for multiple CVEs, including authentication bypass vulnerabilities in TOTOLINK devices and a scanner for Fortinet SSL VPN (CVE-2024-21762). The PoCs demonstrate the vulnerabilities with clear technical details and functional code.

Description

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.

Exploits (7)

github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-20282

This repository contains functional exploit code for multiple CVEs, including authentication bypass vulnerabilities in TOTOLINK devices and a scanner for Fortinet SSL VPN (CVE-2024-21762). The PoCs demonstrate the vulnerabilities with clear technical details and functional code.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: TOTOLINK LR350, TOTOLINK T6, Fortinet SSL VPN
No auth needed
Prerequisites: network access to the target device
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC 1 stars
by skadevare · remote
https://github.com/skadevare/CiscoISE-CVE-2025-20282-POC

This PoC exploits a vulnerability in Cisco ISE by manipulating the `isehourlycron.sh` script to execute arbitrary commands. It includes functionality to reset the system and inject commands via a crafted payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cisco Identity Services Engine (ISE)
No auth needed
Prerequisites: Network access to the target Cisco ISE instance · Ability to send crafted requests to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by pairofglasses · poc
https://github.com/pairofglasses/cve-2025-20282

This repository contains a functional exploit for CVE-2025-20282, targeting Cisco ISE with an unauthenticated RCE via ZIP file upload and JSP webshell deployment. The exploit uploads a malicious JSP file to a vulnerable endpoint and executes commands via a reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cisco Identity Services Engine (ISE)
No auth needed
Prerequisites: Network access to the target · Vulnerable Cisco ISE instance
devstral-2 · analyzed Jun 12, 2026 Full analysis →
nomisec WORKING POC
by tevsho · poc
https://github.com/tevsho/cve-2025-20282

This repository contains a functional exploit for CVE-2025-20282, demonstrating unauthenticated remote code execution (RCE) on Cisco ISE. The exploit uploads a JSP webshell via a ZIP file and executes commands through a crafted HTTP request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cisco Identity Services Engine (ISE)
No auth needed
Prerequisites: Network access to the target · Target running vulnerable Cisco ISE version
devstral-2 · analyzed Jun 02, 2026 Full analysis →
nomisec WORKING POC
by eggpratacurry · poc
https://github.com/eggpratacurry/cve-2025-20282

This repository contains a functional exploit for CVE-2025-20282, targeting Cisco ISE with an unauthenticated RCE via ZIP file upload and JSP webshell deployment. The exploit uploads a malicious JSP file to a vulnerable endpoint and executes commands via a crafted HTTP request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cisco Identity Services Engine (ISE)
No auth needed
Prerequisites: Network access to the target · Vulnerable Cisco ISE instance
devstral-2 · analyzed May 26, 2026 Full analysis →
nomisec WORKING POC
by biggerbangg · poc
https://github.com/biggerbangg/cve-2025-20282

This repository contains a functional exploit for CVE-2025-20282, targeting Cisco ISE with an unauthenticated RCE via ZIP file upload and JSP webshell deployment. The exploit leverages a path traversal vulnerability to drop a webshell and execute commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cisco Identity Services Engine (ISE)
No auth needed
Prerequisites: Network access to the target · Cisco ISE with vulnerable endpoint exposed
devstral-2 · analyzed Apr 18, 2026 Full analysis →
nomisec WORKING POC
by pwnc4t · remote
https://github.com/pwnc4t/cve-2025-20282

This repository contains a functional exploit for CVE-2025-20282, targeting Cisco ISE with an unauthenticated RCE via ZIP file upload and JSP webshell deployment. The exploit leverages a path traversal vulnerability to drop a malicious JSP file and execute arbitrary commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cisco Identity Services Engine (ISE)
No auth needed
Prerequisites: Network access to the target · Cisco ISE with vulnerable file upload endpoint
devstral-2 · analyzed Apr 09, 2026 Full analysis →

Scores

CVSS v3 10.0
EPSS 0.0059
EPSS Percentile 69.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-01-20
CWE
CWE-269
Status published
Products (2)
cisco/identity_services_engine 3.4.0 (2 CPE variants)
cisco/identity_services_engine_passive_identity_connector 3.4.0 (2 CPE variants)
Published Jun 25, 2025
Tracked Since Feb 18, 2026