Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    4 ways to address the failures we found along the US border’s “virtual wall”

    September 22, 2026

    US and China Discuss Alerting Each Other to AI National Security Threats

    September 21, 2026

    The US spent billions on border surveillance. Why can’t it catch people before they die?

    September 21, 2026
    Facebook X (Twitter) Instagram
    Trending
    • 4 ways to address the failures we found along the US border’s “virtual wall”
    • US and China Discuss Alerting Each Other to AI National Security Threats
    • The US spent billions on border surveillance. Why can’t it catch people before they die?
    • AI, Tariffs, Rare Minerals: What to Expect From Trump’s Upcoming Summit With Xi Jinping
    • She died at the San Diego border. A surveillance camera was in plain sight
    • Shortwave Radio Gets a Secure Data Upgrade With HERMES
    • Got an Android Phone? Google Thinks You’ll Probably Want a Googlebook Laptop
    • The Download: investigating deaths at the US border’s “virtual wall”
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Hackers used Cisco zero-day to plant rootkits on network switches (CVE-2025-20352)
    Cybersecurity

    Hackers used Cisco zero-day to plant rootkits on network switches (CVE-2025-20352)

    kirklandc008@gmail.comBy kirklandc008@gmail.comOctober 17, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Hackers used Cisco zero-day to plant rootkits on network switches (CVE-2025-20352)
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors have leveraged a recently patched IOS/IOS XE vulnerability (CVE-2025-20352) to deploy Linux rootkits on vulnerable Cisco network devices.

    “The operation targeted victims running older Linux systems that do not have endpoint detection response solutions,” Trend Micro researchers shared.

    Once a rootkit was implanted, it would set a universal password (containing the word “disco”) and install several hooks onto the IOSd (process) memory space, to make fileless components disappear after a reboot.

    About CVE-2025-20352

    In late September 2025, Cisco fixed an IOS/IOS XE vulnerability (CVE-2025-20352) exploited by attackers in zero-day attacks, but did not share additional details about the attacks.

    CVE-2025-20352, a stack overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE software, could lead to either a DoS condition or remote code execution, and the latter only if the attacker already had high-privileges a vulnerable device.

    “An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks,” Cisco noted, and shared that the attackers were able to get their hands on valid local administrator credentials and use them to achieve remote code execution.

    Researchers’ findings

    Trend Micro discovered that the attackers exploited the flaw in Cisco 9400, 9300, and legacy 3750G series devices.

    They wielded several exploits and targeted both 32-bit and 64-bit platforms. They also attempted to exploit a modified version of an old Telnet vulnerability (CVE-2017-3881), to achieve memory read/write at arbitrary addresses.

    The researchers uncovered several exploits used by the attackers. One was used to install the Linux rootkit, and one to stop trace logging on the target device.

    “Trend investigation also found a UDP controller component used to control the rootkit, and an arp spoofing tool on a Cisco switch,” the researchers shared.

    “The UDP controller provides several powerful management functions: it can toggle log history on or off or delete log records entirely; bypass AAA authentication and bypass VTY access-control lists; enable or disable a universal password; conceal portions of the running configuration; and reset the timestamp of the last running-config write so the configuration appears never to have been changed.”

    The arp spoffing tool can be used to make the traffic meant for the network device be sent to the attacker first.

    What to do?

    Cisco has advised customers to use the Cisco Software Checker or a form in the CVE-2025-20352 security advisory to check whether their devices are running an affected version, and to update them if they are.

    Trend Micro has shared indicators of compromise related to these attacks, but also noted that there is no universal automated tool that can be used determine whether a Cisco switch has been successfully compromised by the ZeroDisco operation (as they call it).

    “If you suspect a switch is affected, we recommend contacting Cisco TAC immediately and asking the vendor to assist with a low-level investigation of firmware/ROM/boot regions,” the researchers advised.

    While the targeted devices may be older ones, the exploits can work on newer ones, as well.

    “Newer switch models provide some protection via Address Space Layout Randomization (ASLR), which reduces the success rate of intrusion attempts; however, it should be noted that repeated attempts can still succeed,” the researchers added.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    Cisco CVE202520352 hackers network plant rootkits switches zeroday
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    How ideas of a vast censorship network moved from the online fringe to Trump policy

    August 8, 2026

    V2X Technology Gets a 5G Cellphone Network Solution

    August 7, 2026

    Indigenous Fiber Network Connects Remote Subarctic Towns

    July 31, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • 4 ways to address the failures we found along the US border’s “virtual wall”
    • US and China Discuss Alerting Each Other to AI National Security Threats
    • The US spent billions on border surveillance. Why can’t it catch people before they die?
    • AI, Tariffs, Rare Minerals: What to Expect From Trump’s Upcoming Summit With Xi Jinping
    • She died at the San Diego border. A surveillance camera was in plain sight

    4 ways to address the failures we found along the US border’s “virtual wall”

    September 22, 2026

    US and China Discuss Alerting Each Other to AI National Security Threats

    September 21, 2026

    The US spent billions on border surveillance. Why can’t it catch people before they die?

    September 21, 2026

    AI, Tariffs, Rare Minerals: What to Expect From Trump’s Upcoming Summit With Xi Jinping

    September 21, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.