CVE-2025-20352
published 2025-09-24CVE-2025-20352: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An…
PriorityP184high7.7CVSS 3.1
AVNACLPRLUINSCCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-10-20
Exploited in the wild
EPSS
37.61%
98.4th percentile
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:
An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only community string or valid SNMPv3 user credentials and administrative or privilege 15 credentials on the affected device. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks.
This vulnerability is due to a stack overflow condition in the SNMP subsystem of the affected software. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system.
Note: This vulnerability affects all versions of SNMP.
Affected
2193 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Hunt for hidden rogue account names matching the pattern dg[3-7]y8[d-h]pk in Cisco device running-config or AAA user databases — these are rootkit-concealed backdoor accounts planted by Operation Zero Disco. ↗
- →Alert on the presence of EEM scripts named CiscoEMX-1 through CiscoEMX-5 in Cisco device configuration — these are rootkit-hidden persistence scripts. ↗
- →Alert on ACLs named EnaQWklg0, EnaQWklg1, or EnaQWklg2 appearing in Cisco device configuration — these are rootkit-hidden ACLs used by the attacker. ↗
- →Detect crafted SNMP packets containing shell command fragments (e.g., '$(ps -a') — the exploit splits OS commands across multiple SNMP packets due to per-packet byte limits. ↗
- →Monitor for unexpected UDP traffic to any port on Cisco switch management IPs — the rootkit acts as a UDP listener on any port, including closed ones, for C2 communication. ↗
- →Detect sudden zeroing of SNMP/syslog history buffer size on Cisco devices — the rootkit disables logging by setting the log size to zero to evade detection. ↗
- →Alert on unexpected changes to the last running-config write timestamp on Cisco devices — the rootkit resets this timestamp to hide configuration modifications. ↗
- →Look for a Linux ELF binary running inside Cisco guest shell performing ARP spoofing — this tool is used to impersonate waystation IPs and bypass internal firewalls. ↗
- →Correlate exploitation attempts against Cisco SNMP (UDP/161) with subsequent Telnet (TCP/23) traffic to the same device — attackers chained CVE-2025-20352 with a modified CVE-2017-3881 Telnet exploit for memory read/write. ↗
- ·64-bit SNMP RCE rootkit installation requires the attacker to be able to run guest shell on the Cisco device at privilege level 15; 32-bit (3750G) exploitation does not require guest shell. ↗
- ·Rootkit components are fileless and volatile — hooks installed into IOSd memory disappear after a reboot, making post-reboot forensics unreliable without low-level firmware/ROM analysis. ↗
- ·Newer Cisco switch models (9400/9300 series) have ASLR which reduces but does not eliminate exploit success — repeated attempts can still succeed. ↗
- ·There is currently no universal automated tool to reliably determine whether a Cisco switch has been compromised by this operation; low-level firmware and ROM region investigation is required. ↗
- ·The rootkit's config-hiding feature (account names, EEM scripts, ACLs) is disabled by default and must be explicitly enabled by the attacker via the UDP C2 channel — absence of hidden items does not confirm a clean device. ↗
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
vulncheck7.7HIGH
cisa7.7HIGH
vendor_cisco7.7HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Lifecycle Services with Cisco
cisa_ics·2025-10-09
Rockwell Automation Lifecycle Services with Cisco
ICS Advisory
##
Rockwell Automation Lifecycle Services with Cisco
Release DateOctober 09, 2025
Alert CodeICSA-25-282-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 6.3
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Rockwell Automation
- Equipment: Industrial Data Center (IDC) with Cisco Switching, IDC-Managed Support contract with Cisco Switching, Network-Managed Support contract with Cisco network switch, Firewall-Managed Support contract with Cisco firewall
- Vulnerability: Stack-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could result in arbitrary code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECT
CISA ICS
Rockwell Automation Stratix
cisa_ics·2025-10-09
Rockwell Automation Stratix
ICS Advisory
##
Rockwell Automation Stratix
Release DateOctober 09, 2025
Alert CodeICSA-25-282-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 6.3
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Rockwell Automation
- Equipment: Stratix 5700, 5400, 5410, 5200, 5800
- Vulnerability: Stack-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could result in arbitrary code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following version of Stratix 5700 is affected:
- Stratix 5700: Version v15.2(8)E7 and prior
- Stratix 5400: Version v15.2(8)E7 and prior
- Stratix 5410: Version v15.2(8)E7 and prior
CISA
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
cisa·2025-09-29·CVSS 7.7
CVE-2025-20352 [HIGH] CWE-121 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
Vulnerability: Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
Affected: Cisco IOS and IOS XE
Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://sec.cl
Cisco
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
vendor_cisco·2025-09-24·CVSS 7.7
CVE-2025-20352 [HIGH] CWE-121 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:
An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials.
An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only communi
Cisco
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20352 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
CVE-2025-20352: Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read
GHSA
GHSA-c924-mch4-p3p3: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:
ghsa_unreviewed·2025-09-24
CVE-2025-20352 [HIGH] CWE-121 GHSA-c924-mch4-p3p3: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:
An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials.
An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only community string or valid SNMPv3 user credentials and administrative or privilege 15 credentials on t
VulnCheck
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
vulncheck·2025·CVSS 7.7
CVE-2025-20352 [HIGH] CWE-121 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system.
Affected: Cisco IOS and IOS XE Software
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: h
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Cisco: Actively exploited firewall flaws now abused for DoS attacks
blogs_bleepingcomputer·2025-11-07·CVSS 9.9
CVE-2025-20362 [CRITICAL] Cisco: Actively exploited firewall flaws now abused for DoS attacks
## Cisco: Actively exploited firewall flaws now abused for DoS attacks
## Sergiu Gatlan
Cisco warned this week that two vulnerabilities, which have been used in zero-day attacks, are now being exploited to force ASA and FTD firewalls into reboot loops.
The tech giant released security updates on September 25 to address the two security flaws, stating that CVE-2025-20362 enables remote threat actors to access restricted URL endpoints without authentication, while CVE-2025-20333 allows authenticated attackers to gain remote code execution on vulnerable devices.
When chained, these vulnerabilities allow remote, unauthenticated attackers to gain complete control over unpatched systems.
The same day, CISA issued an emergency directive ordering U.S. federal agencies to secure their Cisco fi
Bleepingcomputer
Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
blogs_bleepingcomputer·2025-10-16·CVSS 9.8
CVE-2025-20352 [CRITICAL] Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
## Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
## Bill Toulas
Threat actors exploited a recently patched remote code execution vulnerability (CVE-2025-20352) in Cisco networking devices to deploy a rootkit and target unprotected Linux systems.
The security issue leveraged in the attacks affects the Simple Network Management Protocol (SNMP) in Cisco IOS and IOS XE and leads to RCE if the attacker has root privileges.
According to cybersecurity company Trend Micro, the attacks exploited the flaw in Cisco 9400, 9300, and legacy 3750G series devices and deployed rootkits on "older Linux systems that do not have endpoint detection response solutions."
In the original bulletin for CVE-2025-20352, updated on October 6, Cisco tagged the vulnerability as exploited as a zero d
Trendmicro
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
blogs_trendmicro·2025-10-15·CVSS 9.8
CVE-2025-20352 [CRITICAL] Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Exploits & Vulnerabilities
## Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.
By: Dove Chiu, Lucien Chuang Oct 15, 2025 Read time: ( words)
Save to Folio
Key takeaways:
Attackers exploited the Cisco SNMP vulnerability (CVE-2025-20352) to deploy Linux rootkits on older, unprotected systems, allowing remote code execution (RCE) and persistent unauthorised access by setting universal passwords and installing hooks into IOSd memory space.
The operation primarily impacted Cisco 9400, 9300, and legacy 3750G
Trendmicro
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
blogs_trendmicro·2025-10-15·CVSS 9.8
CVE-2025-20352 [CRITICAL] Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Exploits & Vulnerabilities
# Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.
By: Dove Chiu, Lucien Chuang
2025/10/15
Read time: ( words)
Save to Folio
Key takeaways:
- Attackers exploited the Cisco SNMP vulnerability (CVE-2025-20352) to deploy Linux rootkits on older, unprotected systems, allowing remote code execution (RCE) and persistent unauthorized access by setting universal passwords and installing hooks into IOSd memory space.
- The operation primarily impacted Cisco 9400, 9300, and legacy 3750
Trendmicro
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
blogs_trendmicro·2025-10-15·CVSS 9.8
CVE-2025-20352 [CRITICAL] Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Exploits y vulnerabilidades
## Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.
By: Dove Chiu, Lucien Chuang Oct 15, 2025 Read time: ( words)
Save to Folio
Key takeaways:
Attackers exploited the Cisco SNMP vulnerability (CVE-2025-20352) to deploy Linux rootkits on older, unprotected systems, allowing remote code execution (RCE) and persistent unauthorized access by setting universal passwords and installing hooks into IOSd memory space.
The operation primarily impacted Cisco 9400, 9300, and legacy 3750
Trendmicro
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
blogs_trendmicro·2025-10-15·CVSS 9.8
CVE-2025-20352 [CRITICAL] Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Exploits & Vulnerabilities
## Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.
By: Dove Chiu, Lucien Chuang 2025/10/15 Read time: ( words)
Save to Folio
Key takeaways:
Attackers exploited the Cisco SNMP vulnerability (CVE-2025-20352) to deploy Linux rootkits on older, unprotected systems, allowing remote code execution (RCE) and persistent unauthorized access by setting universal passwords and installing hooks into IOSd memory space.
The operation primarily impacted Cisco 9400, 9300, and legacy 3750G s
Trendmicro
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
blogs_trendmicro·2025-10-15·CVSS 9.8
CVE-2025-20352 [CRITICAL] Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Exploits & Vulnerabilities
## Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.
By: Dove Chiu, Lucien Chuang Oct 15, 2025 Read time: ( words)
Save to Folio
Key takeaways:
Attackers exploited the Cisco SNMP vulnerability (CVE-2025-20352) to deploy Linux rootkits on older, unprotected systems, allowing remote code execution (RCE) and persistent unauthorized access by setting universal passwords and installing hooks into IOSd memory space.
The operation primarily impacted Cisco 9400, 9300, and legacy 3750G
Trendmicro
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
blogs_trendmicro·2025-10-15·CVSS 9.8
CVE-2025-20352 [CRITICAL] Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Ausnutzung von Schwachstellen
## Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.
By: Dove Chiu, Lucien Chuang Oct 15, 2025 Read time: ( words)
Save to Folio
Key takeaways:
Attackers exploited the Cisco SNMP vulnerability (CVE-2025-20352) to deploy Linux rootkits on older, unprotected systems, allowing remote code execution (RCE) and persistent unauthorized access by setting universal passwords and installing hooks into IOSd memory space.
The operation primarily impacted Cisco 9400, 9300, and legacy 37
Bleepingcomputer
Cisco warns of IOS zero-day vulnerability exploited in attacks
blogs_bleepingcomputer·2025-09-24·CVSS 6.1
CVE-2025-20352 [MEDIUM] Cisco warns of IOS zero-day vulnerability exploited in attacks
## Cisco warns of IOS zero-day vulnerability exploited in attacks
## Sergiu Gatlan
Cisco has released security updates to address a high-severity zero-day vulnerability in Cisco IOS and IOS XE Software that is currently being exploited in attacks.
Tracked as CVE-2025-20352, the flaw is due to a stack-based buffer overflow weakness found in the Simple Network Management Protocol (SNMP) subsystem of vulnerable IOS and IOS XE software, impacting all devices with SNMP enabled.
Authenticated, remote attackers with low privileges can exploit this vulnerability to trigger denial-of-service (DoS) conditions on unpatched devices. High-privileged attackers, on the other hand, can gain complete control of systems running vulnerable Cisco IOS XE software by executing code as the root user.
"An at
Recorded Future
September 2025 CVE Landscape
blogs_recorded_future·CVSS 7.2
[HIGH] September 2025 CVE Landscape
# September 2025 CVE Landscape
In September 2025, Recorded Future’s Insikt Group® identified sixteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the eighteen identified in August, with the number of Very Critical vulnerabilities also decreasing (11) month over month.
These vulnerabilities have affected the following vendors: Sudo, Libraesva, Fortra, Cisco, Adminer, Google, Dassault Systèmes, Linux, Android, Sitecore, TP-Link, and Meta Platforms.
September was dominated by flaws in Cisco and TP-Link, which together represented six of the sixteen vulnerabilities. Cisco’s IOS, IOS XE, and Secure Firewall products were affected by flaws, including stack-based and classic buffer overflows (CWE-121, CWE-120) and missing authorization
Recorded Future
September 2025 CVE Landscape
blogs_recorded_future·CVSS 7.2
[HIGH] September 2025 CVE Landscape
## September 2025 CVE Landscape
In September 2025, Recorded Future’s Insikt Group® identified sixteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the eighteen identified in August, with the number of Very Critical vulnerabilities also decreasing (11) month over month.
These vulnerabilities have affected the following vendors: Sudo, Libraesva, Fortra, Cisco, Adminer, Google, Dassault Systèmes, Linux, Android, Sitecore, TP-Link, and Meta Platforms.
September was dominated by flaws in Cisco and TP-Link, which together represented six of the sixteen vulnerabilities. Cisco’s IOS, IOS XE, and Secure Firewall products were affected by flaws, including stack-based and classic buffer overflows (CWE-121, CWE-120) and missing authorizatio
2025-09-24
Published
2025-09-29
Added to CISA KEV
Exploited in the wild