Executive brief
Cisco Smart Licensing Utility (CSLU) contains an undocumented static administrative credential. An unauthenticated remote attacker can exploit this by using the hardcoded credentials to log in to the system, gaining full administrative rights over the application API.
Affected products
- Cisco Smart Licensing Utility (CSLU) 2.0.0 up to (excluding) 2.3.0
Timeline
- 2024-09-04: disclosed: Initial NVD publication and Cisco advisory release
- 2025-03-31: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2025-03-31: exploited: Confirmed as exploited in the wild per CISA KEV entry