Cisco has disclosed a zero-day vulnerability (CVE-2025-20352) in the widely used IOS and IOS XE , confirming that the security flaw is being actively exploited online.

This vulnerability is located in the Simple Network Management Protocol (SNMP) subsystem and could allow a remote attacker to achieve code execution (RCE) or cause a denial-of-service (DoS) condition on vulnerable devices.
The vulnerability was discovered during investigation of a Cisco Technical Assistance Center (TAC) support case. It involves a stack overflow condition (CWE-121) within the SNMP subsystem in both Cisco IOS Software and IOS XE. An attacker could trigger this vulnerability by sending a specially crafted SNMP packet (over an IPv4 or IPv6 network) to an affected device.
See also: Hackers exploit vulnerability in Hikvision cameras
Cisco: How serious is the vulnerability?
The advisory, published on September 24, 2025, confirms that all versions of SNMP (v1, v2c, and v3) are vulnerable. The severity of the exploit depends on the attacker's privilege level:
- A low-privileged, but authenticated, remote attacker can cause the affected device to reboot, leading to a DoS condition. This requires access to an SNMPv2c read-only community string or valid SNMPv3 user credentials.
- An attacker with high privileges and administrator credentials or privilege 15 can execute arbitrary code as the root user on devices running IOS XE, essentially gaining complete control of the system.
The Cisco Product Security Incident Response Team (PSIRT) has confirmed the successful exploitation of this vulnerability online. According to the advisory, attackers exploited the vulnerability after first compromising local administrator credentials, demonstrating a chain attack methodology.

This highlights the critical need for strong credential management alongside patching. The vulnerability affects a wide range of Cisco devices running vulnerable versions of IOS and IOS XE software where SNMP is enabled. Some of the products listed are: Meraki MS390 and Cisco Catalyst 9300 Series Switches.
See also: Critical vulnerability in DNN platform allows execution of malicious scripts
Any device with SNMP enabled is considered vulnerable unless specific configurations are in place to block malicious traffic. Administrators can use show running-config to determine if SNMP is enabled on their systems.
Cisco has released software updates to address this vulnerability and strongly recommends that all customers upgrade to a patched version to fully resolve the issue. The advisory clarifies that there are no other workarounds available. However, for organizations that cannot immediately apply the updates, it is recommended that they configure an SNMP view to exclude the affected object IDs (OIDs), preventing the vulnerable code path from being triggered.
Cisco warns that this measure can disrupt network management functions , such as device discovery and hardware inventory monitoring. As a general security measure, Cisco also advises limiting SNMP access to trusted users only .
See also: Critical bugs in Wondershare RepairIt leak user data
Hackers never stop finding security holes
Cisco's disclosure of the CVE-2025-20352 vulnerability once again highlights the risk that network environments face when fundamental protocols, such as SNMP, are targeted. The issue is not limited to its technical dimension, but also impacts the business continuity of organizations that rely on Cisco infrastructure for critical operations.

The worrying thing is that the exploit is already being recorded “in the field”, which confirms that attackers do not just need theoretical knowledge, but are exploiting the loophole in real-world scenarios. The fact that valid credentials are required shows that the attack chain starts with weak identity management, reinforcing the importance of zero trust policies.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Cisco's release of patches was prompt, but for organizations with large networks, immediate upgrades are often not realistic. In these cases, the proposed mitigations are a temporary solution with operational costs. The recommendation is clear: administrators should not limit themselves to patches, but should reevaluate the overall permissions and exposure of SNMP services.
