As many as 2 million Cisco devices affected by actively exploited 0-day

As many as 2 million Cisco devices affected by actively exploited 0-day

A staggering 2 million Cisco devices are at risk due to a critical zero-day vulnerability that can be exploited to remotely crash systems or execute unauthorized code. Cisco disclosed this alarming information on Wednesday, identifying the vulnerability as CVE-2025-20352. This flaw is present in all supported versions of Cisco IOS and Cisco IOS XE, the operating systems that power a wide array of Cisco's networking equipment. This vulnerability is particularly concerning as it can be exploited by users with low privileges to launch denial-of-service attacks, while higher-privileged users could execute malicious code with root access. It has been assigned a severity rating of 7.7 out of 10, indicating a significant risk. The Cisco Product Security Incident Response Team (PSIRT) revealed that they became aware of successful exploits in the wild after local administrator credentials were compromised. In their advisory, Cisco strongly urged customers to upgrade to a patched software version to mitigate this serious risk. The root of the vulnerability lies in a stack overflow error within the IOS component that processes SNMP (Simple Network Management Protocol) data, which is used by routers and other network devices to manage information within a network. Attackers can exploit this flaw by sending specially crafted SNMP packets. To successfully execute malicious code, an attacker would need access to a read-only community string, a form of SNMP authentication that is often pre-configured on devices. Even if modified by administrators, these strings are frequently known within organizations, making them vulnerable to exploitation. Additionally, the attacker must have certain privileges on the compromised systems to achieve remote code execution (RCE) capabilities that operate with root-level permissions.

Sources : Ars Technica

Published On : Sep 25, 2025, 12:50

Startups
Meta's CTO Urges Future Tech Innovators to Start Creating Now

Andrew Bosworth, the Chief Technology Officer of Meta, recently shared valuable insights for college students aspiring t...

Business Insider | Apr 03, 2026, 20:30
Meta's CTO Urges Future Tech Innovators to Start Creating Now
Science
Artemis II Mission Thrives as Astronauts Connect with Earth from Space

As the Artemis II mission entered its third day, the spacecraft's powerful engine had propelled the astronauts into a fa...

Ars Technica | Apr 03, 2026, 22:25
Artemis II Mission Thrives as Astronauts Connect with Earth from Space
Automotive
Tesla's Austin Factory Sees Workforce Cut Amid Declining Sales

Tesla's manufacturing hub near Austin, Texas, has experienced a significant reduction in its workforce, with numbers plu...

TechCrunch | Apr 03, 2026, 21:00
Tesla's Austin Factory Sees Workforce Cut Amid Declining Sales
Computing
Meta's Bold AI Strategy: Transforming Workforce Dynamics and Productivity

Meta is undergoing a significant transformation as it embraces artificial intelligence to enhance productivity and strea...

Business Insider | Apr 03, 2026, 20:00
Meta's Bold AI Strategy: Transforming Workforce Dynamics and Productivity
Science
Ancient Dice Unearth Insights into Native American Understanding of Probability

A groundbreaking study reveals that Native Americans have been engaging in games of chance using dice for over 12,000 ye...

Ars Technica | Apr 03, 2026, 23:00
Ancient Dice Unearth Insights into Native American Understanding of Probability
View All News