As many as 2 million Cisco devices affected by actively exploited 0-day

As many as 2 million Cisco devices affected by actively exploited 0-day

A staggering 2 million Cisco devices are at risk due to a critical zero-day vulnerability that can be exploited to remotely crash systems or execute unauthorized code. Cisco disclosed this alarming information on Wednesday, identifying the vulnerability as CVE-2025-20352. This flaw is present in all supported versions of Cisco IOS and Cisco IOS XE, the operating systems that power a wide array of Cisco's networking equipment. This vulnerability is particularly concerning as it can be exploited by users with low privileges to launch denial-of-service attacks, while higher-privileged users could execute malicious code with root access. It has been assigned a severity rating of 7.7 out of 10, indicating a significant risk. The Cisco Product Security Incident Response Team (PSIRT) revealed that they became aware of successful exploits in the wild after local administrator credentials were compromised. In their advisory, Cisco strongly urged customers to upgrade to a patched software version to mitigate this serious risk. The root of the vulnerability lies in a stack overflow error within the IOS component that processes SNMP (Simple Network Management Protocol) data, which is used by routers and other network devices to manage information within a network. Attackers can exploit this flaw by sending specially crafted SNMP packets. To successfully execute malicious code, an attacker would need access to a read-only community string, a form of SNMP authentication that is often pre-configured on devices. Even if modified by administrators, these strings are frequently known within organizations, making them vulnerable to exploitation. Additionally, the attacker must have certain privileges on the compromised systems to achieve remote code execution (RCE) capabilities that operate with root-level permissions.

Sources : Ars Technica

Published On : Sep 25, 2025, 12:50

Computing
Marvell's Stock Soars 18% Amid Promising AI Growth Forecast

Marvell Technology experienced a remarkable 18% surge in its stock price on Friday, following the release of impressive ...

CNBC | Mar 06, 2026, 16:50
Marvell's Stock Soars 18% Amid Promising AI Growth Forecast
Mobile
Apple Blocks ByteDance Apps for US Users Amid TikTok Ownership Shift

In a significant move, Apple has implemented restrictions preventing iOS users in the United States from accessing apps ...

Ars Technica | Mar 06, 2026, 16:30
Apple Blocks ByteDance Apps for US Users Amid TikTok Ownership Shift
AI
AI's Impact on Jobs: Which Professions Are Most Vulnerable?

Dario Amodei, a prominent figure at Anthropic, has raised concerns about the implications of artificial intelligence on ...

Business Insider | Mar 06, 2026, 17:00
AI's Impact on Jobs: Which Professions Are Most Vulnerable?
AI
Google Affirms Commitment to Anthropic AI Amid Defense Concerns

In a recent announcement, Google has confirmed its intention to continue providing access to Anthropic's artificial inte...

CNBC | Mar 06, 2026, 18:40
Google Affirms Commitment to Anthropic AI Amid Defense Concerns
Science
NASA's DART Mission Successfully Alters Asteroid Orbits and Trajectories

On September 26, 2022, NASA's Double Asteroid Redirection Test (DART) spacecraft made history by colliding with a binary...

Ars Technica | Mar 06, 2026, 19:05
NASA's DART Mission Successfully Alters Asteroid Orbits and Trajectories
View All News