Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software
Cisco has alerted users to a high-severity security vulnerability in IOS and IOS XE software that, under certain situations, might cause a denial-of-service (DoS) issue or enable a remote attacker to run arbitrary code.
After local Administrator credentials were hacked, the organization discovered that the vulnerability, CVE-2025-20352 (CVSS score: 7.7), had been exploited in the wild.
According to the networking equipment major, the problem stems from a stack overflow condition and is based in the Simple Network Management Protocol (SNMP) subsystem.
By sending a specially constructed SNMP packet to an impacted device via IPv4 or IPv6 networks, an authenticated remote attacker could take advantage of the vulnerability. If they have low privileges, this could result in DoS attacks...

