Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    DeepMind Says Its AI Can Predict Hurricanes Earlier Than Everyone Else

    August 6, 2026

    Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery

    August 6, 2026

    The Download: Google’s AI shake-up and Meta’s rogue model

    August 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • DeepMind Says Its AI Can Predict Hurricanes Earlier Than Everyone Else
    • Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
    • The Download: Google’s AI shake-up and Meta’s rogue model
    • AI Hacks Are Bad. AI Worms and Viruses Will Be Worse
    • OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
    • OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
    • IEEE Course on Using AI to Modernize Power Grids
    • The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Hackers used Cisco zero-day to plant rootkits on network switches (CVE-2025-20352)
    Cybersecurity

    Hackers used Cisco zero-day to plant rootkits on network switches (CVE-2025-20352)

    kirklandc008@gmail.comBy kirklandc008@gmail.comOctober 17, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Hackers used Cisco zero-day to plant rootkits on network switches (CVE-2025-20352)
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors have leveraged a recently patched IOS/IOS XE vulnerability (CVE-2025-20352) to deploy Linux rootkits on vulnerable Cisco network devices.

    “The operation targeted victims running older Linux systems that do not have endpoint detection response solutions,” Trend Micro researchers shared.

    Once a rootkit was implanted, it would set a universal password (containing the word “disco”) and install several hooks onto the IOSd (process) memory space, to make fileless components disappear after a reboot.

    About CVE-2025-20352

    In late September 2025, Cisco fixed an IOS/IOS XE vulnerability (CVE-2025-20352) exploited by attackers in zero-day attacks, but did not share additional details about the attacks.

    CVE-2025-20352, a stack overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE software, could lead to either a DoS condition or remote code execution, and the latter only if the attacker already had high-privileges a vulnerable device.

    “An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks,” Cisco noted, and shared that the attackers were able to get their hands on valid local administrator credentials and use them to achieve remote code execution.

    Researchers’ findings

    Trend Micro discovered that the attackers exploited the flaw in Cisco 9400, 9300, and legacy 3750G series devices.

    They wielded several exploits and targeted both 32-bit and 64-bit platforms. They also attempted to exploit a modified version of an old Telnet vulnerability (CVE-2017-3881), to achieve memory read/write at arbitrary addresses.

    The researchers uncovered several exploits used by the attackers. One was used to install the Linux rootkit, and one to stop trace logging on the target device.

    “Trend investigation also found a UDP controller component used to control the rootkit, and an arp spoofing tool on a Cisco switch,” the researchers shared.

    “The UDP controller provides several powerful management functions: it can toggle log history on or off or delete log records entirely; bypass AAA authentication and bypass VTY access-control lists; enable or disable a universal password; conceal portions of the running configuration; and reset the timestamp of the last running-config write so the configuration appears never to have been changed.”

    The arp spoffing tool can be used to make the traffic meant for the network device be sent to the attacker first.

    What to do?

    Cisco has advised customers to use the Cisco Software Checker or a form in the CVE-2025-20352 security advisory to check whether their devices are running an affected version, and to update them if they are.

    Trend Micro has shared indicators of compromise related to these attacks, but also noted that there is no universal automated tool that can be used determine whether a Cisco switch has been successfully compromised by the ZeroDisco operation (as they call it).

    “If you suspect a switch is affected, we recommend contacting Cisco TAC immediately and asking the vendor to assist with a low-level investigation of firmware/ROM/boot regions,” the researchers advised.

    While the targeted devices may be older ones, the exploits can work on newer ones, as well.

    “Newer switch models provide some protection via Address Space Layout Randomization (ASLR), which reduces the success rate of intrusion attempts; however, it should be noted that repeated attempts can still succeed,” the researchers added.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    Cisco CVE202520352 hackers network plant rootkits switches zeroday
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Indigenous Fiber Network Connects Remote Subarctic Towns

    July 31, 2026

    How an overlooked geothermal plant got a second chance

    July 29, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • DeepMind Says Its AI Can Predict Hurricanes Earlier Than Everyone Else
    • Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
    • The Download: Google’s AI shake-up and Meta’s rogue model
    • AI Hacks Are Bad. AI Worms and Viruses Will Be Worse
    • OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

    DeepMind Says Its AI Can Predict Hurricanes Earlier Than Everyone Else

    August 6, 2026

    Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery

    August 6, 2026

    The Download: Google’s AI shake-up and Meta’s rogue model

    August 6, 2026

    AI Hacks Are Bad. AI Worms and Viruses Will Be Worse

    August 6, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.