Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Alcovia Ford Nugget-style six-sleeper Ducato camper van
    • AI is already across your business and its carbon impact probably is too
    • Good Luck Getting a Mac Mini for the Next ‘Several Months’
    • The most severe Linux threat to surface in years catches the world flat-footed
    • Apple Plugs Security Hole That Enabled FBI to Access Deleted Signal Messages on iPhone
    • GPU Performance Comparison Shows Surprising Variability
    • How to Study the Monotonicity and Stability of Variables in a Scoring Model using Python
    • Vision-only manipulation is hitting a wall
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Friday, May 1
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»As many as 2 million Cisco devices affected by actively exploited 0-day
    News

    As many as 2 million Cisco devices affected by actively exploited 0-day

    Editor Times FeaturedBy Editor Times FeaturedSeptember 29, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    As many as 2 million Cisco gadgets are prone to an actively exploited zero-day that may remotely crash or execute code on susceptible programs.

    Cisco said Wednesday that the vulnerability, tracked as CVE-2025-20352, was current in all supported variations of Cisco IOS and Cisco IOS XE, the working system that powers all kinds of the corporate’s networking gadgets. The vulnerability might be exploited by low-privileged customers to create a denial-of-service assault or by higher-privileged customers to execute code that runs with unfettered root privileges. It carries a severity ranking of seven.7 out of a potential 10.

    Exposing SNMP to the Web? Yep

    “The Cisco Product Safety Incident Response Crew (PSIRT) grew to become conscious of profitable exploitation of this vulnerability within the wild after native Administrator credentials had been compromised,” Wednesday’s advisory said. “Cisco strongly recommends that clients improve to a set software program launch to remediate this vulnerability.”

    The vulnerability is the results of a stack overflow bug within the IOS element that handles SNMP (easy community administration protocol), which routers and different gadgets use to gather and deal with details about gadgets inside a community. The vulnerability is exploited by sending crafted SNMP packets.

    To execute malicious code, the distant attacker should have possession of read-only community string, an SNMP-specific type of authentication for accessing managed gadgets. Continuously, such strings ship with gadgets. Even when modified by an administrator, read-only neighborhood strings are sometimes broadly recognized inside a corporation. The attacker would additionally require privileges on the susceptible programs. With that, the attacker can receive RCE (distant code execution) capabilities that run as root.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    The most severe Linux threat to surface in years catches the world flat-footed

    April 30, 2026

    Meta says it might be forced to withdraw its apps from New Mexico if a judge orders it to adopt the state’s proposed safety features (Thomas Barrabi/New York Post)

    April 30, 2026

    when asked whether xAI has ever distilled tech from OpenAI, Elon Musk says the claim is “partly” true (New York Times)

    April 30, 2026

    US officials are preparing a wide-ranging AI policy memo that outlines rules for national security agencies’ AI use, including avoiding single vendors (Bloomberg)

    April 30, 2026

    OpenAI says its models, starting with GPT-5.1, “increasingly mentioned goblins, gremlins, and other creatures”, leading to prompt instructions to mitigate it (OpenAI)

    April 30, 2026

    CFTC Sues Wisconsin in Escalating Fight Over Prediction Market Regulation

    April 30, 2026

    Comments are closed.

    Editors Picks

    Alcovia Ford Nugget-style six-sleeper Ducato camper van

    May 1, 2026

    AI is already across your business and its carbon impact probably is too

    May 1, 2026

    Good Luck Getting a Mac Mini for the Next ‘Several Months’

    April 30, 2026

    The most severe Linux threat to surface in years catches the world flat-footed

    April 30, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    OpenAI’s AI Video App Hits One Million Downloads — and Sparks a Creative Storm

    October 13, 2025

    The Arithmetic of Productivity Boosts: Why Does a “40% Increase in Productivity” Never Actually Work?

    April 7, 2026

    Rubin Observatory: How It Works, and First Images

    June 23, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.