On January 25th, 2025, the Trend Zero Day Initiative (ZDI) received a report from Kentaro Kawane of GMO Cybersecurity by Ierae regarding a deserialization of untrusted data vulnerability in Cisco Identity Services Engine (ISE). This pre-authentication vulnerability existed in the enableStrongSwanTun| Zero Day Initiative
The Wayback Machine - https://web.archive.org/web/20250702221347/https://raw.githubusercontent.com/abrewer251/CVE-2025-20281-2-Cisco-ISE-RCE/refs/heads/main/PoC.py| web.archive.org
Explore how a hard-coded JWT in Cisco IOS XE WLC enables unauthenticated file upload and potential RCE—and how to mitigate it.| Horizon3.ai