Attackers have already exploited the SNMP vulnerability to execute remote code or deny service.
Network admins should quickly patch a vulnerability in Cisco Systems IOS and IOS XE software to remove a stack overflow condition in the software’s Simple Network Management Protocol (SNMP) subsystem or risk nasty attacks, say experts.
“I wouldn’t delay patching,” says David Shipley, head of Canadian security awareness firm Beauceron Security, because with the release of a Cisco warning of the hole “attackers will likely have PoCs (proofs of concept of an exploit) with hours, thanks to AI tools. Delay patching at your own peril.”
[ Related: More Cisco news and insights ]
The vulnerability, CVE-2025-20352, can do the following:
- allow a low privileged authenticated attacker who sends a crafted SNMP packet to an affected device to cause the system to reload, resulting in a denial of service (DoS) condition.
- allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system.
To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials.
To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only community string or valid SNMPv3 user credentials and administrative or privilege 15 credentials on the affected device.
The Cisco Product Security Incident Response Team (PSIRT) became aware of successful exploitation of this vulnerability in the wild after local Administrator credentials were compromised.
“It requires an authenticated user, so at least it’s not an unauthenticated RCE (remote code execution),” said Shipley. The vulnerability has a high CVSS score of 7.7, “but [it’s] not the worst we’ve seen of late.”
Ed Dubrovsky, chief operating officer of US-based incident response firm Cypfer, also noted that a successful attacker would need to be authenticated.
Although many companies still use default credentials on the SNMP protocol level, he said, the requirement to have an additional device authentication to execute the denial of service or RCE means additional complexity for an attacker.
He added that the risk of this being exploited by an insider who has the necessary credentials is almost equal to that of an outsider. In fact, he said, if an outside attacker has the required authentication, an organization would really be in trouble.
The need, based on the CVE, for multi level authentication for both SNMP and a device means that the threat actor is not a script kiddie, but rather someone more motivated, likely with a more technical skill set, who can then also leverage that device access to move laterally to the high value systems, he said.
“At the end of the day, a Cisco device at the edge is likely to have no company data on it, and threat actors that are primarily motivated by financial gains need data and system access to exfiltrate and lock. APT [advanced persistent threat] and nation state actors present a different threat, of course, but it is probable that such environments would present additional layered defenses to further reduce the risk from this CVE.
“The bigger question is whether this vulnerability can then be chained to obtain system access that contains precious data,” he added. “While this might be developed later on, it will likely require a different level of access and hence might pose a somewhat reduced risk overall, again due to the additional complexity.”
This vulnerability affects all versions of SNMP in unpatched devices running Cisco’s IOS and IOS XE software.
Note that Meraki MS390 and Cisco Catalyst 9300 Series Switches running Meraki CS 17 and earlier are also affected. The flaw is fixed in Cisco IOS XE Software Release 17.15.4a.
Unaffected are Cisco devices running IOS XR or NX-OS software.
Cisco has released software updates to fix the bug. Admins who can’t immediately patch can mitigate the issue by only allowing trusted users to have SNMP access on an affected system. They are also advised to monitor affected systems by using the show SNMP host command in the command line interface (CLI).
The company warns in its advisory, “Administrators can disable the affected OIDs (object identifiers) on a device. Not all software will support the OID that is listed in Cisco’s mitigation. If the OID is not valid for specific software, then it is not affected by this vulnerability. Excluding these OIDs may affect device management through SNMP, such as discovery and hardware inventory.”
Cisco’s advisory is part of the September 2025 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: September 2025 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication.




