GettyImages-1276687348.jpg
– Getty

Attackers are taking advantage of a vulnerability in Cisco’s Simple Network Management Protocol (SNMP), which allows malicious rootkits to be installed on network hardware.

According to findings from Trend Micro, the campaign involves Linux rootkits deployed on SNMP devices, allowing remote code execution and persistent unauthorized access. This is done through the setting up of universal passwords and malicious hooks in the memory space of the Cisco IOS daemon (IOSd) software platform, which runs on devices operating the Cisco IOS XE operating system.

According to the researchers, the affected devices at risk from the exploit are Cisco Catalyst 9300 and 9400 Series Switches, and the legacy 3750G series, with both 32-bit and 64-bit switch builds affected.

The campaign, known as Operation Zero Disco, targets a critical vulnerability in Cisco's IOS and IOS XE software, designated CVE-2025-20352, as revealed by Cisco last month. The vulnerability has a broad impact across all devices running IOS or IOS XE software, allowing remote attackers with basic SNMP access to crash devices, while those with higher administrative credentials could execute arbitrary code as a root user, gaining complete control of the affected systems.

The vulnerability stems from a stack overflow that can be initiated by sending specific SNMP packets via IPv4 or IPv6.

Users were advised to download software updates as a fix, with no workarounds available for the issue.

How the attack works

Using Cisco-provided data, Trend Micro discovered the malware establishes a universal password containing the word “disco," in a possible play on the name Cisco. The bug then installs multiple hooks in the IOSd, which results in fileless components disappearing after a system reboot. This takes advantage of a modified legacy vulnerability, designated CVE-2017-3881, to enable memory read/write.

Via a concealed UDP controller that can receive commands even on closed ports, attackers are able to erase log records, evade access restrictions, conceal configuration elements, and alter timestamps to obscure their activities.

Trend Micro advised that newer switch models provide some protection via Address Space Layout Randomization (ASLR), which randomly rearranges the memory addresses of key data areas associated with a process.

The researchers also advised against using public SNMP community strings, and recommended disabling Telnet access while implementing intrusion prevention systems.

The ArcaneDoor adversary

The exploit comes days after Cisco was pressed by U.S. Senator Bill Cassidy (R-LA) over a separate exploit in its firewall wares that may have allowed for a nation-state backed breach.

In a letter to Cisco CEO Chuck Robbins last week, the senator referenced a recent Emergency Directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in response to zero-day exploits targeting Cisco's Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices.

The attacks, which take advantage of a remote code execution vulnerability (CVE-2025-20333) and a privilege escalation flaw (CVE-2025-20362), have been linked to the ArcaneDoor campaign, which Cisco reported on early last year.

Censys potentially pinned the campaign on a China-based actor, with connections “to multiple major Chinese networks and the presence of Chinese-developed anti-censorship software.”

Cisco was given until October 27 to respond to Cassidy's queries on its response to the situation.