Urgent: Cisco Backdoor Admin Account Actively Exploited in CSLU – Patch Now


# Cisco Warns of Critical Backdoor Vulnerability Under Active Exploitation

Cisco has issued an urgent warning to administrators regarding a critical vulnerability in the Cisco Smart Licensing Utility (CSLU) that exposes a built-in backdoor admin account currently being exploited by attackers.

The vulnerability (CVE-2024-20439), patched in September, involves an undocumented static credential that allows unauthenticated attackers to remotely access vulnerable systems with administrative privileges through the CSLU application’s API. The flaw only affects systems running vulnerable CSLU releases and is only exploitable when the application is actively running.

Security researcher Nicholas Starke reverse-engineered the vulnerability shortly after Cisco released patches, publishing technical details including the decoded hardcoded password. This publication likely facilitated the attacks that Cisco confirmed in March 2025.

“Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate this vulnerability,” the company stated in its updated advisory.

## Attack Campaign Details

Threat actors are reportedly chaining CVE-2024-20439 with a second critical vulnerability (CVE-2024-20440), an information disclosure flaw that allows unauthenticated attackers to access log files containing sensitive data, including API credentials, by sending crafted HTTP requests.

Johannes Ullrich, Dean of Research at SANS Technology Institute, identified a campaign targeting exposed CSLU instances online. On Monday, CISA added the backdoor vulnerability to its Known Exploited Vulnerabilities Catalog, requiring U.S. federal agencies to secure their systems by April 21.

This isn’t Cisco’s first backdoor issue, as similar hardcoded credentials have previously been discovered in other Cisco products including IOS XE, Wide Area Application Services, Digital Network Architecture Center, and Emergency Responder software.

Share This Article