Cisco Wireless Access Point Software Device Analytics Action Frame Injection Vulnerability
TL;DR 📌
A medium-severity vulnerability has been identified in Cisco Wireless Access Point Software related to Device Analytics action frame processing. An unauthenticated adjacent attacker could exploit this vulnerability to inject arbitrary information into wireless 802.11 action frames. Cisco has released fixed software, but no workarounds are available.
What happened 🕵️♂️
A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point Software allows an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This issue arises from insufficient verification checks of incoming 802.11 action frames. Successful exploitation could modify the Device Analytics data of valid wireless clients connected to the same wireless controller.
Affected products 🖥️
The following Cisco products are affected if they are running a vulnerable release of Cisco AP Software with Device Analytics enabled:
- 6300 Series Embedded Services APs
- Aironet 1540 Series APs
- Aironet 1560 Series APs
- Aironet 1800 Series APs
- Aironet 2800 Series APs
- Aironet 3800 Series APs
- Aironet 4800 APs
- Catalyst 9100 APs
- Catalyst IW6300 Heavy Duty Series APs
- Integrated APs on 1100 Integrated Services Routers (ISRs)
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 17.11 and earlier | Migrate to a fixed release. | |
| 17.12 | 17.12.6 | |
| 17.13 | Migrate to a fixed release. | |
| 17.14 | Migrate to a fixed release. | |
| 17.15 | 17.15.4 | |
| 17.16 | Migrate to a fixed release. | |
| 17.17 | Migrate to a fixed release. | |
| 17.18 | Not vulnerable. | |
| 1.0 | Initial public release. | |
| Cisco Wireless LAN Controller | 17.12.6 | 17.11 and earlier |
| Cisco Wireless LAN Controller | 17.15.4 | 17.15 |
Workarounds 🧯
There are no workarounds available to mitigate this vulnerability.
Risk in context 🎯
The vulnerability has a CVSS score of 4.3, categorized as Medium severity. While exploitation requires an adjacent attacker, the potential to modify Device Analytics data poses a risk to network integrity and client data accuracy.
Fast facts ⚡
- Vulnerability ID: CVE-2025-20364
- CVSS Score: 4.3 (Medium)
- Attack Vector: Adjacent network access required
- Exploitation Impact: Potential modification of Device Analytics data
For leadership 🧭
Executive summary. Cisco access points running Device Analytics can be tricked into recording false client data by anyone within Wi-Fi range, undermining the accuracy of network visibility tools rather than granting network access. This is a medium-severity issue with fixed software already available, so it can be scheduled into a normal patch cycle rather than treated as an emergency.
Why it matters:
- Affects a broad range of deployed hardware, including Aironet 1540/1560/1800/2800/3800/4800 series, Catalyst 9100 and IW6300 APs, and integrated APs on 1100 ISRs, wherever Device Analytics is enabled.
- Exploitation needs no authentication, only radio proximity to a vulnerable AP, so any device within wireless range could inject forged action frames.
- Impact is limited to corrupting Device Analytics records for legitimate clients on the same wireless controller, reducing confidence in client visibility data used for network management rather than enabling direct client compromise.
- No workaround exists, so the only mitigation path is upgrading to the fixed release for each affected train.
Now / Next / Later:
- Now: Identify which Cisco AP Software trains in your estate have Device Analytics enabled and check them against the fixed-release table.
- Next: Upgrade affected controllers and access points to the first fixed release for their train (e.g. 17.12.6, 17.15.4, or later), migrating off unsupported trains like 17.11, 17.13, 17.14, 17.16 and 17.17.
- Later: Include Device Analytics status and AP software train in routine wireless configuration audits so future advisories affecting this feature can be triaged quickly.