Skip to main content
Vulnerability Database/CVE-2025-20167

CVE-2025-20167: Cisco Crosswork Network Controller XSS Flaw

CVE-2025-20167 is a cross-site scripting vulnerability in Cisco Crosswork Network Controller allowing authenticated attackers to inject malicious code. This article covers technical details, affected versions, and available mitigations.

Published:

CVE-2025-20167 Overview

CVE-2025-20167 is a stored cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) and Cisco Crosswork Network Controller. The flaw results from insufficient validation of user-supplied input in specific pages of the interface. An authenticated attacker with at least low-privileged credentials can inject malicious script that executes in the browser context of another user viewing the affected page. Cisco has not released software updates that address this vulnerability, and no vendor workarounds are available.

Critical Impact

A successful exploit allows an attacker to execute arbitrary script code in the context of the management interface or access sensitive browser-based information such as session tokens.

Affected Products

  • Cisco Common Services Platform Collector (CSPC) versions 2.11, 2.11.0.1, 2.11.0.2, 2.11.0.3, and 30.1.1-0
  • Cisco Crosswork Network Controller (multiple versions per vendor advisory)
  • Deployments exposing the web-based management interface to authenticated users

Discovery Timeline

  • 2025-01-08 - CVE-2025-20167 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-20167

Vulnerability Analysis

The vulnerability is a cross-site scripting flaw classified under [CWE-86: Improper Neutralization of Invalid Characters in Identifiers in Web Pages]. The web-based management interface accepts user-supplied input and renders it back to interface pages without adequate encoding or sanitization. When another authenticated user loads the affected page, the injected payload executes in that user's browser session.

Exploitation requires authentication and user interaction, and the attack crosses a trust boundary because the injected script runs in the security context of the management application. This can expose session cookies, cross-site request forgery tokens, and other sensitive browser-accessible data belonging to higher-privileged administrators.

Root Cause

The root cause is insufficient input validation and output encoding in the affected pages of the CSPC and Crosswork Network Controller management interface. User-supplied values are stored and later reflected into HTML responses without neutralizing script constructs, enabling script injection.

Attack Vector

The attack vector is network-based and requires an authenticated, low-privileged account on the affected device. The attacker submits a crafted payload through an input field on a vulnerable interface page. When a targeted user, typically an administrator, browses the page containing the stored payload, the script executes with that user's privileges in the management interface. See the Cisco Security Advisory: CSPC XSS and the Cisco Security Advisory: XWORK XSS for the vendor's technical description.

No public proof-of-concept exploit is available, and this vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2025-20167

Indicators of Compromise

  • Unexpected <script> tags, javascript: URIs, or HTML event handlers stored in CSPC or Crosswork Network Controller configuration fields
  • Administrator session activity originating from unusual IP addresses shortly after visiting an affected interface page
  • Outbound HTTP requests from administrator browsers to attacker-controlled domains referencing the management interface as the origin

Detection Strategies

  • Review web server and application audit logs for POST requests from low-privileged accounts containing HTML or script metacharacters targeting the CSPC or Crosswork management interface
  • Inspect stored configuration data and user-supplied fields in the interface for embedded markup that should not appear in normal input
  • Correlate authenticated sessions with anomalous browser behavior such as unexpected API calls to privileged endpoints

Monitoring Recommendations

  • Enable and centralize access logging for the CSPC and Crosswork Network Controller web interfaces
  • Alert on authentication events for low-privileged accounts followed by administrative actions in short time windows
  • Monitor for changes to management interface content and configuration objects outside approved change windows

How to Mitigate CVE-2025-20167

Immediate Actions Required

  • Restrict access to the CSPC and Crosswork Network Controller management interfaces to trusted administrative networks and jump hosts only
  • Audit all accounts with access to the web interface and remove or disable any unnecessary low-privileged accounts
  • Enforce unique, high-entropy credentials and multi-factor authentication for all users of the management interface
  • Instruct administrators to avoid browsing arbitrary pages of the interface from browsers used for other sensitive activity

Patch Information

At the time of publication, Cisco has not released software updates that address CVE-2025-20167. Monitor the Cisco Security Advisory: CSPC XSS and the Cisco Security Advisory: XWORK XSS for updated fixed-release information.

Workarounds

  • Cisco has stated that no workarounds address this vulnerability
  • As compensating controls, place the management interface behind a VPN or bastion host and enforce strict network access control lists
  • Deploy a reverse proxy or web application firewall in front of the interface to filter script payloads in request parameters where feasible
  • Use dedicated administrative browsers or profiles to reduce the impact of session token theft

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.