Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco Patches Zero-Day Flaw Affecting Routers and Switches

Cisco Patches Zero-Day Flaw Affecting Routers and Switches

Posted on September 25, 2025September 25, 2025 By CWS

Cisco on Wednesday introduced patches for 14 vulnerabilities in IOS and IOS XE, together with a bug that has been exploited within the wild.

The exploited flaw, tracked as CVE-2025-20352 (CVSS rating of seven.7), is described as a stack overflow situation within the Easy Community Administration Protocol (SNMP) subsystem of IOS and IOS XE that may be exploited by sending crafted SNMP packets to a susceptible router or swap.

Attackers with low privileges, Cisco explains, can exploit the problem to trigger a denial-of-service (DoS) situation. Excessive-privileged attackers may exploit it to execute arbitrary code remotely as the foundation consumer.

“To execute code as the foundation consumer, the attacker will need to have the SNMPv1 or v2c read-only neighborhood string or legitimate SNMPv3 consumer credentials and administrative or privilege 15 credentials on the affected gadget,” Cisco notes in its advisory.

All gadgets operating susceptible IOS and IOS XE releases are affected, in addition to Meraki MS390 and Catalyst 9300 sequence switches operating Meraki CS 17 and earlier releases.

Cisco urges customers to replace their gadgets to a patched launch as quickly as potential, because the safety defect has been exploited within the wild by attackers utilizing compromised administrator credentials.

The recent spherical of IOS and IOS XE patches, introduced as a part of Cisco’s semiannual bundled publication, resolves eight different high-severity vulnerabilities that would result in DoS situations, code execution throughout boot, command execution with root privileges, authentication bypass, and knowledge leaks.

The remaining 5 bugs, all medium-severity, may result in DoS situations, XSS assaults, command execution with root privileges, entry management listing (ACL) bypass, or entry to the gadget’s public-key infrastructure (PKI) server.Commercial. Scroll to proceed studying.

Cisco says proof-of-concept (PoC) exploit code exists for 2 of those points, tracked as CVE-2025-20240 and CVE-2025-20149, however factors out that it isn’t conscious of their exploitation.

Three different medium-severity bugs patched this week have an effect on Cisco’s SD-WAN vEdge, Entry Level, and Wi-fi Entry Level (AP) software program and will result in ACL bypass, IPv6 gateway tampering, and Machine Analytics knowledge tampering.

Cisco says it isn’t conscious of any of those flaws being exploited within the wild. Extra info could be discovered on the corporate’s safety advisories web page.

Associated: GeoServer Flaw Exploited in US Federal Company Hack

Associated: SonicWall Updates SMA 100 Home equipment to Take away Overstep Malware

Associated: SolarWinds Makes Third Try at Patching Exploited Vulnerability

Associated: Fortra Patches Crucial GoAnywhere MFT Vulnerability

Security Week News Tags:Affecting, Cisco, Flaw, Patches, Routers, Switches, ZeroDay

Post navigation

Previous Post: Numerous Applications Using Google’s Firebase Platform Leaking Highly Sensitive Data
Next Post: NVIDIA Merlin Vulnerability Allow Attacker to Achieve Remote Code Execution With Root Privileges

Related Posts

Rising Tides: Kelley Misata on Bringing Cybersecurity to Nonprofits Rising Tides: Kelley Misata on Bringing Cybersecurity to Nonprofits Security Week News
766,000 Impacted by Data Breach at Dealership Software Provider Motility 766,000 Impacted by Data Breach at Dealership Software Provider Motility Security Week News
Predatory Sparrow Burns  Million on Iranian Crypto Exchange in Cyber Shadow War Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War Security Week News
Hackers Earn Over  Million at Pwn2Own Berlin 2025 Hackers Earn Over $1 Million at Pwn2Own Berlin 2025 Security Week News
Niobium Raises  Million for FHE Hardware Acceleration Niobium Raises $23 Million for FHE Hardware Acceleration Security Week News
Jazz Secures M to Revolutionize AI-Powered DLP Jazz Secures $61M to Revolutionize AI-Powered DLP Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • India to Prohibit Chinese CCTV Sales by 2026
  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • India to Prohibit Chinese CCTV Sales by 2026
  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark