Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
embedded-device-vulnerabilityperimeter-device-exposurewidely-deployed-product-advisoryactively-exploited-vulnerability

Cisco IOS XE Flaws Enable Remote Code Execution and Device Takeover

Updated 2mo agoFirst seen Apr 14, 20263 sources

Multiple vulnerabilities in Cisco IOS and Cisco IOS XE devices have exposed routers, switches, access points, and Catalyst 9000 platforms to severe compromise, including remote code execution, denial of service, access control bypass, privilege escalation, secure boot bypass, cross-site scripting, and memory corruption. Traficom highlighted newly disclosed flaws such as CVE-2025-20334 and CVE-2025-20363, which may allow arbitrary code execution, and urged organizations to update affected products in line with Cisco’s version-specific advisories.

The warning follows earlier real-world attacks against internet-exposed Cisco IOS XE Web GUI instances, where attackers exploited CVE-2023-20198 and CVE-2023-20273 to create unauthorized administrator accounts, install a backdoor implant, and seize full control of devices. Cisco Talos reported the campaign affected exposed systems internationally, with tens of thousands of vulnerable devices identified online, while Finnish authorities said some domestic devices had already been backdoored and advised restricting Web GUI access to trusted networks or removing public internet exposure entirely.

Share:
Cisco IOS XE Flaws Enable Remote Code Execution and Device Takeover
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Sep 26, 20259mo ago

Authorities recommend updating affected Cisco IOS and IOS XE products

The 2025 advisory recommended that organizations update affected Cisco products in line with Cisco’s version-specific guidance and advisories. The notice highlighted management interfaces, SNMP, TACACS+, certificate services, and Cisco Catalyst 9000 platforms among the affected areas.

Cisco discloses multiple new IOS and IOS XE vulnerabilities

A later security notice described multiple vulnerabilities affecting Cisco IOS and IOS XE devices, including remote code execution, denial of service, access control bypass, privilege escalation, secure boot bypass, cross-site scripting, and memory corruption flaws. Notable issues included CVE-2025-20334 and CVE-2025-20363, both of which could enable remote arbitrary code execution.

Oct 27, 20233y ago

Finnish authorities warn owners of exposed Cisco IOS XE devices

Finland’s Kyberturvallisuuskeskus alerted local owners of internet-exposed Cisco IOS XE devices and advised restricting Web GUI access to trusted networks or removing public exposure. It said the number of detected vulnerable devices in Finland had fallen from about 40 to under 20, though some already showed signs of the backdoor malware.

Oct 22, 20233y ago

Cisco begins releasing security updates for IOS XE zero-days

Cisco started issuing security updates for the exploited Cisco IOS XE vulnerabilities as the campaign unfolded. The updates began on October 22, 2023, according to the reference.

Oct 1, 20233y ago

Cisco Talos identifies backdoor implant and chained CVEs in campaign

Cisco Talos reported that compromised Cisco IOS XE devices contained unauthorized user accounts and a backdoor malware implant. It later identified the campaign as exploiting both CVE-2023-20198 and CVE-2023-20273.

Attackers exploit Cisco IOS XE zero-day via exposed Web GUI

A critical intrusion campaign targeted Cisco IOS XE devices whose Web GUI was exposed to the public internet. The exploitation allowed attackers to create a full administrator account, take control of affected routers, switches, and access points, and install malware.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.