Cisco has alerted users to a high-severity security vulnerability in IOS and IOS XE software that, under certain situations, might cause a denial-of-service (DoS) issue or enable a remote attacker to run arbitrary code.
After local Administrator credentials were hacked, the organization discovered that the vulnerability, CVE-2025-20352 (CVSS score: 7.7), had been exploited in the wild.
According to the networking equipment major, the problem stems from a stack overflow condition and is based in the Simple Network Management Protocol (SNMP) subsystem.
By sending a specially constructed SNMP packet to an impacted device via IPv4 or IPv6 networks, an authenticated remote attacker could take advantage of the vulnerability. If they have low privileges, this could result in DoS attacks; if they have high privileges, it could cause arbitrary code execution as root and ultimately take over the vulnerable system.
Cisco did point out that the following requirements must be fulfilled for this to occur read more about Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
