Executive brief
A vulnerability exists in the networking software used by many Cisco routers and switches to manage device health and performance. An attacker with valid management credentials could send a malicious message that causes the device to crash and restart, or in some cases, take full control of the system. This could lead to significant network outages or unauthorized access to sensitive corporate traffic.
Technical details
A stack-based buffer overflow (CWE-121) exists in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software. The vulnerability is triggered by sending a specially crafted SNMP packet over IPv4 or IPv6 to an affected device. Exploitation requires authentication: low-privileged attackers with read-only community strings or SNMPv3 credentials can trigger a system reload (DoS), while high-privileged attackers (Privilege 15) can achieve remote code execution as the root user. This vulnerability has been reported as exploited in the wild.
Affected products
- Cisco IOS All versions of SNMP subsystem
- Cisco IOS XE All versions of SNMP subsystem
- Cisco IOS XE SD-WAN 16.9.1, 16.9.2, 16.9.3, 16.9.4
Timeline
- 2025-09-29: advisory: Initial disclosure by Cisco and NVD
- 2025-09-29: kev added: Added to CISA Known Exploited Vulnerabilities catalog