Cisco Systems sign outside its hadquarters in San Jose, CA
– Getty Images

Network administrators have been urged to immediately patch a critical vulnerability in Cisco's IOS and IOS XE software that could allow attackers to compromise network devices or crash them entirely.

Designated CVE-2025-20352, the vulnerability in the Simple Network Management Protocol (SNMP) subsystem presents two potential threats: remote attackers with basic SNMP access can crash devices, while those with higher administrative credentials could execute arbitrary code as a root user, gaining complete control of the affected systems.

The flaw stems from a stack overflow condition that can be triggered by sending specially crafted SNMP packets over IPv4 or IPv6 networks.

The vulnerability has a broad impact across Cisco's product line, affecting all devices running IOS or IOS XE software, including Meraki MS390 and Cisco Catalyst 9300 Series Switches running Meraki CS 17 and earlier.

The vendor confirmed that no workaround will address the issue.

“All devices that have SNMP enabled and have not explicitly excluded the affected object ID (OID) should be considered vulnerable,” the advisory reads.

The flaw does not impact Cisco products running IOS XR or NX-OS software.

SNMP is a widely used protocol that allows network administrators to collate and manage their various network devices on IP networks remotely. IT teams can use it to collect and organize performance data, configure settings, and troubleshoot issues across their network infrastructure.

An SNMP-based exploit affecting retired Cisco networking devices was recently identified as being used by a Russian espionage group.

Attacks linked to the Russian Federal Security Service's (FSB) Center 16 were unearthed in August by Cisco Talos researchers. The threat actors were using the flaw in similar ways to this latest issue in causing denial-of-service conditions and executing arbitrary code.