Hackers Deploy Linux Rootkits via Cisco SNMP Flaw in “Zero Disco’ Attacks

Details of a new campaign that used a recently discovered security hole in Cisco IOS and IOS XE software to install Linux rootkits on older, unprotected computers have been made public by cybersecurity researchers.

CVE-2025-20352 (CVSS score: 7.7) is a stack overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could be weaponized to enable an authenticated, remote attacker to execute arbitrary code by sending crafted SNMP packets to a vulnerable device. Trend Micro has codenamed this activity Operation Zero Disco. No known threat actor or group has been implicated in the intrusions.

Cisco fixed the vulnerability late last month, but not before real-world assaults took advantage of it as a zero-day vulnerability.

According to researchers Dove Chiu and Lucien Chuang, the operation mostly affected Cisco 9400, 9300, and vintage 3750G series devices. There were also efforts to use a customized Telnet vulnerability read more about Hackers Deploy Linux Rootkits via Cisco SNMP Flaw in “Zero Disco’ Attacks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *