Critical: 2 Million Cisco Devices Vulnerable to Actively Exploited Zero-Day

2025-09-25
Critical: 2 Million Cisco Devices Vulnerable to Actively Exploited Zero-Day

A critical zero-day vulnerability (CVE-2025-20352) affecting up to 2 million Cisco devices is actively being exploited. The vulnerability, present in all supported versions of Cisco IOS and IOS XE, allows remote attackers to crash devices or execute arbitrary code. Exploitation leverages a stack overflow in the SNMP component, requiring a read-only community string and system privileges. Cisco urges immediate upgrades to patched software releases.

Tech Cisco