Drooid Logo
Back to today’s briefing

Story perspectives

Critical Cisco Zero-Day Exposes Devices to Remote Attacks

9/25/2025

28 2 Full Breakdown

1 of 1

Story summary
  • Cisco disclosed CVE-2025-20352, a zero-day in Cisco IOS and IOS XE exploited in the wild, enabling DoS and remote code execution via an SNMP (Simple Network Management Protocol) stack overflow.
  • Low-privilege attackers trigger reloads; high-privilege attackers execute code as root.
  • Affected devices: Cisco Catalyst 9300 Series switches and Meraki MS390; immediate software updates recommended; no complete workarounds exist; CVSS 7.7.