CVE-2025-20365 - CVE House
Back to Database
Status published Medium CVE-2025-20365

A vulnerability in the IPv6 Router Advertisement (RA) packet processing...

Vulnerability Description

A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on an affected device. This vulnerability is due to a logic error in the processing of IPv6 RA packets that are received from wireless clients. An attacker could exploit this vulnerability by associating to a wireless network and sending a series of crafted IPv6 RA packets. A successful exploit could allow the attacker to temporarily change the IPv6 gateway of an affected device. This could also lead to intermittent packet loss for any wireless clients that are associated with the affected device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-20365

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Aironet Access Point Software (IOS XE Controller)
Vulnerable Versions:
16.10.1e, 16.10.1, 17.1.1t, 17.1.1s, 17.1.1, 16.11.1a, 16.11.1, 16.11.1c, 16.11.1b, 16.12.1s, 16.12.4, 16.12.1, 16.12.2s, 16.12.1t, 16.12.4a, 16.12.5, 16.12.3, 16.12.6, 16.12.8, 16.12.7, 16.12.6a, 17.3.1, 17.3.2a, 17.3.3, 17.3.4, 17.3.5, 17.3.2, 17.3.4c, 17.3.5a, 17.3.5b, 17.3.6, 17.3.7, 17.3.8, 17.3.8a, 17.2.1, 17.2.1a, 17.2.3, 17.2.2, 17.5.1, 17.4.1, 17.6.1, 17.6.2, 17.6.3, 17.6.4, 17.6.5, 17.6.6, 17.6.6a, 17.6.5a, 17.6.7, 17.6.8, 17.10.1, 17.9.1, 17.9.2, 17.9.3, 17.9.4, 17.9.4a, 17.9.5, 17.9.6, 17.9.7, 17.7.1, 17.8.1, 17.11.1, 17.12.1, 17.12.2, 17.12.3, 17.12.5, 17.13.1, 17.14.1, 17.15.1

Timeline

Official Publish: September 24th, 2025
Last Modified: October 15th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.