• News/
  • https://www.theregister.com/2025/09/25/zeroday_deja_vu_another_cisco/

Zero-day deja vu as another Cisco IOS bug comes under attack

The Register
·
Carly Page
·
Published Sep 25, 2025
·
Updated

Cisco has confirmed a new IOS and IOS XE zero-day, the latest in a string of flaws that attackers have been quick to weaponize. Cisco's IOS, the networking software workhorse running across countless switches and routers, has long been a punching bag for attackers, most notably in a 2023 spree that left thousands of boxes compromised. The networking behemoth added yet another high-severity IOS flaw to the tally this week. Tracked as CVE-2025-20352, the vulnerability lives in the Simple Network Management Protocol (SNMP) subsystem and can be tripped with a malicious packet over IPv4 or IPv6 whenever SNMP is enabled. Attackers with low-privilege SNMP creds can crash a device, while those with higher-privilege access can run arbitrary code as root – a straight shot to total box compromise. "The Cisco Product Security Incident Response Team (PSIRT) became aware of successful exploitation of this vulnerability in the wild after local Administrator credentials were compromised," the company said. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability." Cisco hasn't named the culprits behind the exploitation or disclosed how widespread the attacks are, and it also failed to respond to The Register's questions in time for publication. There's no clever workaround this time, and the only reliable mitigation is to patch. Cisco suggests admins can buy themselves a little time by restricting SNMP access to trusted management hosts, b...

Read full article

Affected Software

2 affected components
Cisco IOS
Cisco IOS XE

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203