#VU116083 Stack-based buffer overflow in Cisco IOS XE - CVE-2025-20352
Published: September 24, 2025 / Updated: September 25, 2025
Cisco IOS XE
Cisco Systems, Inc
Description
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to a boundary error within the SNMP subsystem. A remote privileged user can send specially crafted SNMP packets to the affected device, trigger a stack-based buffer overflow and execute arbitrary code with root privileges.
Note, the vulnerability is being actively exploited in the wild.