https://arstechnica.com/security/2025/09/as-many-as-2-million-cisco-devices-affected-by-actively-exploited-0-day/ Skip to content Ars Technica home Sections Forum Subscribe Search * AI * Biz & IT * Cars * Culture * Gaming * Health * Policy * Science * Security * Space * Tech * Feature * Reviews * AI * Biz & IT * Cars * Culture * Gaming * Health * Policy * Science * Security * Space * Tech Forum Subscribe Story text Size [Standard] Width * [Standard] Links [Standard] * Subscribers only Learn more Pin to story Theme * HyperLight * Day & Night * Dark * System Search dialog... Sign In Sign in dialog... Sign in YOU'VE PATCHED, YES? As many as 2 million Cisco devices affected by actively exploited 0-day Search shows 2 million vulnerable Cisco SNMP interfaces exposed to the Internet. Dan Goodin - Sep 25, 2025 8:43 am | 22 Cisco Systems headquarters in San Jose, California, US, on Monday, Aug. 14, 2023. Cisco Systems headquarters in San Jose, California, US, on Monday, Aug. 14, 2023. Cisco Systems headquarters in San Jose, California. Credit: Getty Cisco Systems headquarters in San Jose, California. Credit: Getty Text settings Story text Size [Standard] Width * [Standard] Links [Standard] * Subscribers only Learn more Minimize to nav As many as 2 million Cisco devices are susceptible to an actively exploited zero-day that can remotely crash or execute code on vulnerable systems. Cisco said Wednesday that the vulnerability, tracked as CVE-2025-20352, was present in all supported versions of Cisco IOS and Cisco IOS XE, the operating system that powers a wide variety of the company's networking devices. The vulnerability can be exploited by low-privileged users to create a denial-of-service attack or by higher-privileged users to execute code that runs with unfettered root privileges. It carries a severity rating of 7.7 out of a possible 10. Exposing SNMP to the Internet? Yep "The Cisco Product Security Incident Response Team (PSIRT) became aware of successful exploitation of this vulnerability in the wild after local Administrator credentials were compromised," Wednesday's advisory stated. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability." The vulnerability is the result of a stack overflow bug in the IOS component that handles SNMP (simple network management protocol), which routers and other devices use to collect and handle information about devices inside a network. The vulnerability is exploited by sending crafted SNMP packets. To execute malicious code, the remote attacker must have possession of read-only community string, an SNMP-specific form of authentication for accessing managed devices. Frequently, such strings ship with devices. Even when modified by an administrator, read-only community strings are often widely known inside an organization. The attacker would also require privileges on the vulnerable systems. With that, the attacker can obtain RCE (remote code execution) capabilities that run as root. "If you get RCE as root, you're getting higher than admin privileges," independent researcher Kevin Beaumont wrote in an online interview. "You're not supposed to be able to get root on those devices." To perform a DOS, all an attacker needs is the read-only community string or valid SNMPv3 user credentials. Making SNMP devices accessible to Internet interfaces is frowned upon because it unnecessarily exposes networks to precisely these sorts of risks. As Beaumont noted on Mastodon, however, the Shodon search engine indicates that more than 2 million devices around the world do just that. [cisco-shodan-1024x601] Credit: Kevin Beaumont The best protection against exploitation is to install an update Cisco has released. For those who can't do so right away, they can mitigate the risk by allowing only trusted users to have SNMP access and to monitor Cisco devices using the snmp command in the terminal window. There are no workarounds. There are also no additional details about in-the-wild exploitation. CVE-2025-20352 is one of 14 vulnerabilities Cisco patched in its September update release. Eight of the vulnerabilities carried severity ratings ranging from 6.7 to 8.8. Photo of Dan Goodin Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 22 Comments Staff Picks Soko Soko "SNMP interfaces exposed to the Internet" FFS Agreed. The old saw from us greybeards is "SNMP stands for "Security's Not My Problem". September 25, 2025 at 1:34 pm Comments Forum view Loading Loading comments... Prev story Next story Most Read 1. Listing image for first story in Most Read: Astra's Chris Kemp woke up one recent morning and chose violence 1. Astra's Chris Kemp woke up one recent morning and chose violence 2. 2. "Screwworm is dangerously close": Flesh-eating parasites just 70 miles from US 3. 3. When "no" means "yes": Why AI chatbots can't process Persian social etiquette 4. 4. As many as 2 million Cisco devices affected by actively exploited 0-day 5. 5. Anti-vaccine allies cheer as Trump claims shots have "too much liquid" Customize Ars Technica has been separating the signal from the noise for over 25 years. With our unique combination of technical savvy and wide-ranging interest in the technological arts and sciences, Ars is the trusted source in a sea of information. After all, you don't need to know everything, only what's important. More from Ars * About Us * Staff Directory * Newsletters * General FAQ * Posting Guidelines * RSS Feeds Contact * Contact us * Advertise with us * Reprints Manage Preferences (c) 2025 Conde Nast. All rights reserved. Use of and/or registration on any portion of this site constitutes acceptance of our User Agreement and Privacy Policy and Cookie Statement and Ars Technica Addendum and Your California Privacy Rights. Ars Technica may earn compensation on sales from links on this site. Read our affiliate link policy. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Conde Nast. Ad Choices