Cisco disclosed a high-severity zero-day vulnerability, CVE-2025-20352, affecting the SNMP subsystem in IOS and IOS XE software, which is being actively exploited in the wild. The flaw, a stack-based buffer overflow, allows authenticated remote attackers with low privileges to cause denial-of-service conditions, while high-privileged attackers can achieve remote code execution as root on vulnerable IOS XE devices. Cisco confirmed that attackers have exploited this vulnerability after compromising local administrator credentials, highlighting the risk of credential theft and chained attacks. The vulnerability affects all devices with SNMP enabled, including Meraki MS390 and Cisco Catalyst 9300 Series Switches, and impacts all SNMP versions (v1, v2c, v3). Cisco has released security updates and strongly urges customers to upgrade immediately, as no workarounds exist beyond restricting SNMP access to trusted users.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On 2025-09-26, Rockwell Automation published a product advisory noting the impact of Cisco's CVE-2025-20352 on Stratix-branded equipment. The notice extended the incident to downstream industrial networking products that incorporate affected Cisco technology.
On 2025-09-26, CERT-EU published an advisory on CVE-2025-20352, reiterating active exploitation and recommending immediate updates, assessment for compromise, and restricting SNMP access from untrusted networks. The advisory summarized Cisco's technical details, affected products, and available fixed release information.
On 2025-09-25, a public GitHub repository released an SNMP exposure checking tool for CVE-2025-20352 using onesixtyone and a parser. The tool provided defenders and researchers with practical assessment capability to identify potentially exposed Cisco IOS and IOS XE devices.
By 2025-09-25, external reporting highlighted the potential scale of exposure, estimating that as many as 2 million Cisco devices could be affected by the actively exploited zero-day. The estimate underscored the broad enterprise and service-provider risk posed by widespread SNMP use on IOS and IOS XE systems.
Subsequent reporting clarified that the vulnerability affects SNMP-enabled IOS and IOS XE devices across multiple product lines, including Meraki MS390 and Catalyst 9300 series running certain releases, while IOS XR and NX-OS are not affected. Reports also noted that all SNMP versions, including v1, v2c, and v3, are impacted.
At disclosure, Cisco released software updates for affected products, including IOS XE 17.15.4a, and advised customers to use its Software Checker to identify vulnerable versions. Cisco said there were no complete workarounds beyond patching, though restricting SNMP access to trusted networks or users could reduce exposure temporarily.
On 2025-09-24, Cisco disclosed CVE-2025-20352, a high-severity stack-based buffer overflow in the SNMP subsystem of IOS and IOS XE that was being actively exploited in the wild. The flaw can be triggered with crafted SNMP packets and may lead to denial of service or, with higher privileges, code execution as root.
18 references tracked. Mallory keeps watching after this page renders.
cert.europa.eu
Open sourcescworld.com
Open sourcerockwellautomation.com
Open sourcearstechnica.com
Open sourcethecyberthrone.in
Open sourcerunzero.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.