Cyber Criminals Exploit Cisco SNMP Flaw to Deploy Rootkit on Switches
When cyber criminals go after routers and switches, it's not noise. It's control.This week, reports confirmed that threat actors are exploiting a critical vulnerability in Cisco's SNMP implementation (CVE 2025 20352) to deploy a rootkit on network switches. It's another reminder that the infrastructure we rely on to see and defend our networks can also be turned against us. At Critical Path Security, we've seen how these attacks evolve. A simple SNMP exposure turns into silent persistence, lateral movement, and data manipulation inside critical environments. This one is especially dangerous. What Happened Cisco IOS and IOS XE systems running certain builds are vulnerable to remote code execution through their SNMP stack. Once cyber criminals reach the SNMP interface, often left open for device management, they can execute code as root. The exploit, active in the wild before Cisco's advisory, targets several popular switch families: 9400, 9300, and the legacy 3750G.…