Cisco Access Point Software Intermittent IPv6 Gateway Change Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 4.3 Security Advisory

TL;DR 📌

A medium-severity vulnerability has been identified in Cisco Access Point Software that could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on affected devices. There are no workarounds available, and users are advised to upgrade to fixed software releases.

What happened 🕵️‍♂️

A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to change the IPv6 gateway on affected devices. This vulnerability arises from a logic error in processing IPv6 RA packets received from wireless clients. An attacker could exploit this by associating with a wireless network and sending crafted IPv6 RA packets, potentially leading to intermittent packet loss for associated wireless clients.

Affected products 🖥️

The following Cisco products are affected if running a vulnerable release of Cisco Access Point Software:

  • 6300 Series Embedded Services Access Points (APs)
  • Aironet 1540 Series APs
  • Aironet 1560 Series APs
  • Aironet 1800 Series APs
  • Aironet 2800 Series APs
  • Aironet 3800 Series APs
  • Aironet 4800 APs
  • Catalyst 9100 APs
  • Catalyst IW6300 Heavy Duty Series APs
  • Integrated APs on 1100 Integrated Services Routers (ISRs)

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
17.8 and earlier Migrate to a fixed release.
17.9 17.9.7
17.10 Migrate to a fixed release.
17.11 Migrate to a fixed release.
17.12 17.12.5
17.13 Migrate to a fixed release.
17.14 Migrate to a fixed release.
17.15 17.15.2
17.16 Not vulnerable.
17.17 Not vulnerable.
17.18 Not vulnerable.
1.0 Initial public release.

Workarounds 🧯

There are no workarounds that address this vulnerability.

Risk in context 🎯

The vulnerability has a CVSS score of 4.3, classified as Medium severity. The risk is primarily associated with unauthenticated access from adjacent networks, which could lead to temporary changes in the IPv6 gateway, impacting network availability for connected clients.

Fast facts ⚡

  • Vulnerability: Cisco Access Point Software Intermittent IPv6 Gateway Change Vulnerability
  • CVSS Score: 4.3 (Medium)
  • Exploitation: Requires unauthenticated access from adjacent networks
  • Impact: Potential intermittent packet loss for wireless clients
  • Workarounds: None available

For leadership 🧭

Executive summary. Cisco access points across the Aironet, Catalyst 9100, and IW6300 lines can have their IPv6 gateway changed by any device associated to the wireless network, causing intermittent packet loss for other users. There is no workaround, so remediation depends entirely on scheduling firmware upgrades; treat this as routine patching rather than urgent, given the medium severity and lack of known exploitation.

Why it matters:

  • Any client already associated with the wireless network can send crafted IPv6 RA packets to the AP without further authentication, exploiting a logic flaw in how the AP processes router advertisements from wireless clients.
  • The affected range spans nearly the entire current Cisco AP portfolio, including 6300 Series Embedded Services APs, Aironet 1540/1560/1800/2800/3800/4800, Catalyst 9100, Catalyst IW6300, and integrated APs on 1100 ISRs.
  • Impact is availability, not data compromise: an altered IPv6 gateway causes intermittent packet loss for other wireless clients associated with the same AP.
  • No workaround exists, so exposure persists on any train from 17.8 and earlier through 17.14 (excluding the specific fixed 17.9.7, 17.12.5 releases) until the device is upgraded.

Now / Next / Later:

  • Now: Identify which Cisco AP models and IOS XE Controller software trains are deployed in your wireless estate and check each against the fixed-release table to see if it falls in an affected train.
  • Next: During the next maintenance window, upgrade affected APs to the first fixed release for their train — 17.9.7, 17.12.5, or 17.15.2 — or migrate off any train marked for migration (17.8 and earlier, 17.10, 17.11, 17.13, 17.14).
  • Later: Add IOS XE Controller AP firmware versions to routine patch-tracking cycles so future IPv6 RA-handling fixes are picked up automatically rather than requiring an ad hoc audit.