Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Campaign ×2 Advisory/Mitigation Security Patch Release

Cisco IOS/IOS XE SNMP Zero-Day Exploitation and Operation Zero Disco

Updated 16.10.2025 21:13
Case score 71
Members 5 First seen 24.09.2025 19:52 Latest activity 16.10.2025 21:13

Overview

Exploitation of **Cisco IOS and IOS XE** **CVE-2025-20352** has moved from zero-day disclosure into a campaign story in which **Operation Zero Disco** used the SNMP flaw to compromise network devices and plant persistence. Available reporting describes **Linux rootkits**, **IOSd** memory hooks, and follow-on abuse of a modified **CVE-2017-3881** path on older Cisco gear, especially **9400**, **9300**, and legacy **3750G** systems. Cisco has issued fixed releases and interim SNMP-restriction guidance, but available evidence does not identify the operator or quantify victim count. The immediate priority is patching exposed **IOS/IOS XE** devices and reviewing potentially affected systems for persistence and configuration tampering.
Latest development Open development history 3 earlier developments Trend Micro discloses Operation Zero Disco Cisco IOS rootkit campaign Trend Micro disclosed Operation Zero Disco, a campaign that weaponized CVE-2025-20352 against Cisco IOS Software and IOS XE Software as a zero-day to deploy Linux rootkits on older, unprotected systems. The activity primarily targeted Cisco 9400, 9300, and legacy 3750G series devices, used modified Telnet exploitation based on CVE-2017-3881, and enabled remote code execution and persistent unauthorized access through universal passwords and hooks in Cisco IOS daemon (IOSd) memory space, with spoofed IPs and Mac email addresses used in the intrusions.
  1. Earlier development

    Operation Zero Disco exploits Cisco IOS and IOS XE

    Trend Micro disclosed Operation Zero Disco, a campaign that exploited CVE-2025-20352 in Cisco IOS Software and IOS XE Software as a zero-day to deploy Linux rootkits on older, unprotected systems. The operation primarily impacted Cisco 9400, 9300, and legacy 3750G series devices, and also included attempts to exploit a modified Telnet vulnerability based on CVE-2017-3881 to gain memory access, remote code execution, and persistent unauthorized access through universal passwords and hooks in IOSd memory space.

  2. Earlier development

    Cisco SNMP rootkit campaign disclosed

    A Cisco network-device rootkit campaign used CVE-2025-20352 against exposed Cisco SNMP services to install Linux rootkits, embed hooks into IOSd memory, and create a universal password based on “disco” for persistent unauthorized access; the same activity also used a modified Telnet flaw based on CVE-2017-3881, a UDP controller, and memory-access techniques that concealed configuration changes on Cisco 9400 series, 9300 series, and legacy 3750G devices.

  3. Earlier development

    Cisco releases fixes for exploited IOS and IOS XE zero-day

    Cisco issued security updates for Cisco IOS and IOS XE Software to remediate CVE-2025-20352, a high-severity zero-day stack-based buffer overflow in the SNMP subsystem affecting devices with SNMP enabled. Cisco said the vulnerability is being exploited in attacks, that crafted SNMP packets over IPv4 or IPv6 can trigger denial-of-service conditions on unpatched devices, and that high-privileged attackers may gain root code execution on vulnerable Cisco IOS XE systems; Cisco recommends upgrading to a fixed release or temporarily limiting SNMP access to trusted users.

Signals

Impact signals
Exploitation
CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

1 listed

Malware context

1 families

Technical intelligence

Existing Case data

Member happenings

Vulnerability Cisco IOS and IOS XE Software SNMP stack-based buffer overflow denial-of-service flaw (CVE-2025-20352)
Updated 24.09.2025 19:52 Lead Contribution 66
Exploitation Active Exploitation Data Type Passwords CVSS 9.9 Critical Patch Patch Available

**CVE-2025-20352** is a **Cisco IOS and IOS XE** **SNMP** stack-based buffer overflow that was **exploited in the wild** before Cisco’s fix, and later activity showed **Operation Zero Disco** using it to deploy **Linux rootkits** on **older, unprotected systems**. The campaign primarily affected **Cisco 9400, 9300, and legacy 3750G series devices**, and also included attempts to abuse a modified **Telnet** flaw based on **CVE-2017-3881** for memory access. The attacks enabled **remote code execution** and **persistent unauthorized access** through universal passwords and hooks in **IOSd** memory space.

Campaign Cisco network-device rootkit campaign
Updated 16.10.2025 18:00 Scoring Support Contribution 2
Campaign Active Patch Patch Available

A **Cisco** network-device **rootkit campaign** is exploiting **CVE-2025-20352** and a modified **CVE-2017-3881** Telnet flaw to gain persistent, unauthorized access on exposed devices. The operation matters because it can hide changes, bypass authentication, and survive long enough to enable follow-on movement across **Cisco 9400**, **9300**, and **3750G** environments. It has also been observed against older Linux hosts, showing a multi-stage access path rather than a one-off exploit.

Campaign Operation Zero Disco Cisco IOS/IOS XE rootkit campaign
Updated 16.10.2025 14:38 Scoring Support Contribution 2
Campaign Active Patch Patch Available

A **new campaign** dubbed **Operation Zero Disco** exploited **CVE-2025-20352** against **Cisco IOS Software** and **IOS XE Software**, enabling **Linux rootkits** and persistent access on vulnerable devices. The activity mattered because it was used as a **zero-day** before Cisco's patch, and it primarily hit **Cisco 9400, 9300, and legacy 3750G** series systems. It also included follow-on attempts using a modified **Telnet** flaw and stealthy infrastructure to broaden access and persistence.

Security Patch Release Cisco security patch release for CVE-2025-20352
Updated 24.09.2025 19:52 Context
Exploitation Active Exploitation CVSS 7.7 High Urgency High Patch Patch Available

**Cisco** released **security updates** for **Cisco IOS and IOS XE Software** to fix **CVE-2025-20352**, a **zero-day** in the **SNMP subsystem** that was **exploited in the wild**. The flaw is a **stack overflow** in routers and switches that can be triggered with **crafted SNMP packets**; low-privileged attackers could cause **DoS**, while high-privileged attackers could achieve **remote code execution as root** on affected devices, including **Meraki MS390** and **Catalyst 9300** switches running **Meraki CS 17 and earlier**. Cisco said the vulnerability was fixed in **Cisco IOS XE Software Release 17.15.4a** and urged administrators to **update to a patched release** as soon as possible. Cisco also said operators who cannot upgrade immediately should **limit SNMP access** to trusted users as a temporary mitigation, and the same release addressed **13 other vulnerabilities**.

Advisory/Mitigation Cisco SNMP mitigation guidance for CVE-2025-20352
Updated 25.09.2025 09:30 Context
Exploitation Active Exploitation CVSS 7.7 High Urgency Immediate Patch Patch Available

**Cisco** issued mitigation guidance for **CVE-2025-20352** on **SNMP-enabled IOS and IOS XE systems**, warning administrators to reduce exposure on devices that remain vulnerable. The guidance matters because the flaw is **actively exploited** and can enable **DoS** or even **root code execution** under specific conditions. Cisco's immediate advice is to **restrict SNMP access**, **monitor affected systems**, and **disable the affected OIDs** where supported.