ARSTECHNICA.COM
'zero-day'

As many as 2 million Cisco devices affected by actively exploited 0-day

SUMMARY

Up to 2 million Cisco devices are at risk due to a zero-day vulnerability, identified as CVE-2025-20352, affecting Cisco IOS and IOS XE systems. This flaw allows low-privileged users to launch denial-of-service attacks and higher-privileged users to execute code with root access, rated 7.7 out of 10 in severity.

Cisco's advisory highlights successful exploitation after local Administrator credentials were compromised. The vulnerability stems from a stack overflow in the IOS SNMP component, exploited via crafted SNMP packets.

To mitigate risks, Cisco recommends upgrading to the fixed software release. Alternatives include restricting SNMP access to trusted users. More than 2 million devices remain exposed, making this a significant security concern.


▶︎ Click here for more breaking news