• News/
  • https://www.bleepingcomputer.com/news/security/cisco-warns-of-ios-zero-day-vulnerability-exploited-in-attacks/

Cisco warns of IOS zero-day vulnerability exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Sep 24, 2025
·
Updated

Cisco has released security updates to address a high-severity zero-day vulnerability in Cisco IOS and IOS XE Software that is currently being exploited in attacks. Tracked as CVE-2025-20352, the flaw is due to a stack-based buffer overflow weakness found in the Simple Network Management Protocol (SNMP) subsystem of vulnerable IOS and IOS XE software, impacting all devices with SNMP enabled. Authenticated, remote attackers with low privileges can exploit this vulnerability to trigger denial-of-service (DoS) conditions on unpatched devices. High-privileged attackers, on the other hand, can gain complete control of systems running vulnerable Cisco IOS XE software by executing code as the root user. "An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks," Cisco said in a Wednesday advisory. "The Cisco Product Security Incident Response Team (PSIRT) became aware of successful exploitation of this vulnerability in the wild after local Administrator credentials were compromised. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability." While there are no workarounds to address this vulnerability besides applying the patches released today, Cisco said that administrators who can't immediately upgrade the vulnerable software can temporarily mitigate the issue by limiting SNMP access on an affected system to trusted users. "To fully remediate this vulnerabilit...

Read full article

Affected Software

2 affected components
Cisco IOS
Cisco IOS XE

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a high-severity zero-day vulnerability in Cisco IOS and IOS XE Software that is currently being exploited in attacks.

2

What security implications are discussed?

The article highlights the potential risks associated with the stack-based buffer overflow vulnerability that could allow unauthorized access to affected systems.

3

What products or software are affected?

The affected products include Cisco IOS and Cisco IOS XE Software.

4

What is the identifier for the vulnerability mentioned in the article?

The vulnerability is tracked as CVE-2025-20352.

5

What action has Cisco taken in response to this vulnerability?

Cisco has released security updates to address the vulnerability and mitigate its exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203