Cisco IOS/IOS XE SNMP Zero-Day Exploitation and Operation Zero Disco
Case score 71
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 71
- Main story score
- 66
- Related evidence lift
- +5 / 20
- Contributing updates
- 2
- Context updates
- 2
- Vulnerability Anchors the exploited Cisco IOS/IOS XE SNMP flaw and core risk. main
- Advisory Mitigation Adds interim mitigation guidance for exposed SNMP-enabled systems. context
- Campaign Adds persistence and tradecraft details, including memory hooks and modified Telnet use. contributes
- Campaign Confirms Operation Zero Disco used the flaw as a zero-day and deployed rootkits. contributes
Overview
Latest development Open development history Trend Micro discloses Operation Zero Disco Cisco IOS rootkit campaign Trend Micro disclosed Operation Zero Disco, a campaign that weaponized CVE-2025-20352 against Cisco IOS Software and IOS XE Software as a zero-day to deploy Linux rootkits on older, unprotected systems. The activity primarily targeted Cisco 9400, 9300, and legacy 3750G series devices, used modified Telnet exploitation based on CVE-2017-3881, and enabled remote code execution and persistent unauthorized access through universal passwords and hooks in Cisco IOS daemon (IOSd) memory space, with spoofed IPs and Mac email addresses used in the intrusions.
-
Operation Zero Disco exploits Cisco IOS and IOS XE
Trend Micro disclosed Operation Zero Disco, a campaign that exploited CVE-2025-20352 in Cisco IOS Software and IOS XE Software as a zero-day to deploy Linux rootkits on older, unprotected systems. The operation primarily impacted Cisco 9400, 9300, and legacy 3750G series devices, and also included attempts to exploit a modified Telnet vulnerability based on CVE-2017-3881 to gain memory access, remote code execution, and persistent unauthorized access through universal passwords and hooks in IOSd memory space.
-
Cisco SNMP rootkit campaign disclosed
A Cisco network-device rootkit campaign used CVE-2025-20352 against exposed Cisco SNMP services to install Linux rootkits, embed hooks into IOSd memory, and create a universal password based on “disco” for persistent unauthorized access; the same activity also used a modified Telnet flaw based on CVE-2017-3881, a UDP controller, and memory-access techniques that concealed configuration changes on Cisco 9400 series, 9300 series, and legacy 3750G devices.
-
Cisco releases fixes for exploited IOS and IOS XE zero-day
Cisco issued security updates for Cisco IOS and IOS XE Software to remediate CVE-2025-20352, a high-severity zero-day stack-based buffer overflow in the SNMP subsystem affecting devices with SNMP enabled. Cisco said the vulnerability is being exploited in attacks, that crafted SNMP packets over IPv4 or IPv6 can trigger denial-of-service conditions on unpatched devices, and that high-privileged attackers may gain root code execution on vulnerable Cisco IOS XE systems; Cisco recommends upgrading to a fixed release or temporarily limiting SNMP access to trusted users.