Umbrella, Secure Access and Duo
CVE-2025-20258: A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to…
A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitrary commands into emails that are sent by the service.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Cisco Duo N/A | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitrary commands into emails that are sent by the service. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting arbitrary commands into a portion of an email that is sent by the service. A successful exploit could allow the attacker to send emails that contain malicious content to unsuspecting users.
Exploitation
The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.