Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cisco SNMP Vulnerability Actively Exploited to Install Linux Rootkits

Cybersecurity researchers have identified an active attack campaign known as "Operation Zero Disco," which exploits a critical vulnerability in Cisco’s Simple Network Management Protocol (SNMP) implementation. The vulnerability, referenced as…

Cybersecurity researchers have identified an active attack campaign known as "Operation Zero Disco," which exploits a critical vulnerability in Cisco’s Simple Network Management Protocol (SNMP) implementation. The vulnerability, referenced as CVE-2025-20352 , enables remote code execution and the deployment of sophisticated Linux rootkits on vulnerable network devices.

The vulnerability primarily affects older Cisco switch models, including the 9400 series, 9300 series, and legacy 3750G devices, which lack modern endpoint detection and response capabilities.

CVE ID Affected Product Vulnerability Type Severity

CVE-2025-20352 Cisco IOS XE Software (32-bit and 64-bit switch builds) SNMP Buffer Overflow in Authframework OID Critical

CVE-2025-20352 affects both 32-bit and 64-bit Cisco switch builds, allowing attackers to achieve remote code execution through malicious SNMP packets.
Charles Nolan · Thehackingpost

Successful exploitation can grant attackers persistent unauthorized access to compromised systems, enabling them to hide malicious activity and evade detection. CVE-2025-20352 affects both 32-bit and 64-bit Cisco switch builds, allowing attackers to achieve remote code execution through malicious SNMP packets. Once a device is compromised, the malware installs a rootkit that creates fileless backdoor components. These components remain active during normal operation and are designed to evade detection.

Researchers identified that attackers use spoofed IP addresses and MAC email addresses to obscure their activities. While newer switch models incorporate Address Space Layout Randomization (ASLR) to reduce successful intrusion rates, repeated exploitation attempts can still breach these defenses.

Trend Micro researchers recovered several distinct exploits from compromised Linux systems. For 32-bit devices, attackers deployed SNMP exploits capable of installing rootkits and a modified Telnet vulnerability based on CVE-2017-3881. On 64-bit switch builds, threat actors required level 15 privilege access to run guest shell functionality before installing fileless backdoors. The attack methodology demonstrates advanced network intrusion techniques designed to bypass multiple security layers.

Advertisement

After gaining initial access through the SNMP vulnerability, attackers can remotely disable logging functions, assign waystation IP addresses to ports connected to protected zones, and perform ARP spoofing to redirect legitimate traffic while forcing original systems offline. The UDP controller provides extensive management capabilities, including toggling log history, bypassing AAA authentication and VTY access-control lists, enabling universal passwords, and concealing portions of running configurations.

Cisco has contributed forensic analysis to the investigation, and organizations are urged to contact Cisco TAC immediately if compromise is suspected.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories