Cisco IOS XE Wireless Controller Software Unauthorized User Deletion Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 6.5 Security Advisory

TL;DR 📌

A vulnerability in the Cisco IOS XE Wireless Controller Software allows authenticated remote attackers to delete user accounts, including those with administrative privileges. This issue arises from insufficient access control in the lobby ambassador web interface. No workarounds are available, but Cisco has released software updates to address the vulnerability.

What happened 🕵️‍♂️

Cisco has identified a vulnerability in the lobby ambassador web interface of its IOS XE Wireless Controller Software. This flaw enables authenticated attackers to remove arbitrary user accounts from affected devices by exploiting insufficient access control. The vulnerability can only be exploited if the attacker has obtained credentials for a lobby ambassador account, which is not configured by default.

Affected products 🖥️

The following Cisco products are affected if they are running a vulnerable release of Cisco IOS XE Wireless Controller Software and have lobby ambassador user accounts enabled:

  • Catalyst 9800-CL Wireless Controllers for Cloud
  • Catalyst 9800 Embedded Wireless Controllers for Catalyst 9300, 9400, and 9500 Series Switches
  • Catalyst 9800 Series Wireless Controllers
  • Embedded Wireless Controllers on Catalyst Access Points

Fixed software 🔧

Upgrade to at least the first fixed release in your train (or later):

Product / Release Train First Fixed Release Notes
ISE / ISE-PIC 1.0 Initial public release.

Workarounds 🧯

There are no workarounds that address this vulnerability.

Risk in context 🎯

The vulnerability has a CVSS score of 6.5, categorized as MEDIUM severity. While it requires authenticated access to exploit, the potential to delete user accounts, including those with administrative privileges, poses a significant risk to network security.

Fast facts ⚡

  • Vulnerability ID: CVE-2025-20190
  • CVSS Score: 6.5 (MEDIUM)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  • Exploitation: Requires valid lobby ambassador credentials
  • No workarounds available

For leadership 🧭

Executive summary. Anyone holding a lobby ambassador login on affected Catalyst 9800 wireless controllers can remove other users’ accounts, including administrators, potentially locking staff out of management access. There’s no workaround, so patching should be scheduled at the next available change window rather than left open-ended.

Why it matters:

  • The flaw sits in the lobby ambassador web interface, a low-privilege role meant only for guest account management, yet it can delete any user account on the controller, including admins.
  • Affected devices include Catalyst 9800-CL, 9800 embedded controllers on 9300/9400/9500 switches, and embedded controllers on Catalyst access points.
  • Loss of administrator accounts on a wireless controller could disrupt the ability to manage or recover the device during an incident.
  • Exploitation requires only a valid lobby ambassador credential, an account type that is not enabled by default but may exist in guest Wi-Fi provisioning setups.

Now / Next / Later:

  • Now: Check whether lobby ambassador accounts are configured on any Catalyst 9800 or embedded wireless controller and, if not needed, disable or remove them.
  • Next: Upgrade Cisco IOS XE Wireless Controller Software to a fixed release during the next scheduled maintenance window, since no workaround exists.
  • Later: Review who holds lobby ambassador and other delegated-admin roles on wireless controllers and tighten provisioning so low-privilege accounts cannot be created or retained without justification.