Cisco IOS/IOS XE Smart Install actively exploited remote code execution flaw (CVE-2018-0171)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2018-0171 is an actively exploited vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software. It enables remote code execution and denial-of-service risk on exposed Cisco networking devices, especially when systems are unpatched or end-of-life. Cisco has urged customers to move to a fixed software release or disable Smart Install if patching is not possible. A later joint advisory from NSA, FBI, CISA and other agencies says Russian FSB Center 16 hackers have also been targeting routers with weak SNMP settings to reach critical infrastructure, and it references the same CVE-2018-0171 exploitation thread since November 2021.
Related Happenings
FCC Barix radio equipment hardening notice
Advisory/Mitigation
H score33
First: 27.11.2025 18:45
Last: 27.11.2025 18:45
Sources 1
About this happening:
The FCC urged broadcasters using Barix network audio devices to harden exposed radio transmission paths after hijacking incidents enabled bogus emergency tones and off...
FCC Barix radio equipment hardening notice
Advisory/MitigationAbout this happening: The FCC urged broadcasters using Barix network audio devices to harden exposed radio transmission paths after hijacking incidents enabled bogus emergency tones and off...
Cisco Secure Firewall ASA/FTD mitigation for CVE-2025-20333 and CVE-2025-20362
Advisory/Mitigation
H score53
First: 06.11.2025 16:58
Last: 06.11.2025 16:58
Sources 1
About this happening:
Cisco urged customers to apply updates for Cisco Secure Firewall ASA and FTD devices susceptible to CVE-2025-20333 and CVE-2025-20362, after a new attack v...
Cisco Secure Firewall ASA/FTD mitigation for CVE-2025-20333 and CVE-2025-20362
Advisory/MitigationAbout this happening: Cisco urged customers to apply updates for Cisco Secure Firewall ASA and FTD devices susceptible to CVE-2025-20333 and CVE-2025-20362, after a new attack v...
Cisco IOS XE BadCandy exploitation wave
Exploitation Wave
H score40
First: 31.10.2025 17:38
Last: 31.10.2025 17:38
Sources 1
About this happening:
Ongoing BadCandy exploitation of unpatched Cisco IOS XE devices in Australia has left over 150 devices compromised and enabled repeat re-infection on previously al...
Cisco IOS XE BadCandy exploitation wave
Exploitation WaveAbout this happening: Ongoing BadCandy exploitation of unpatched Cisco IOS XE devices in Australia has left over 150 devices compromised and enabled repeat re-infection on previously al...
Cisco network-device rootkit campaign
Campaign
H score42
First: 16.10.2025 18:00
Last: 16.10.2025 18:00
Sources 1
About this happening:
A Cisco network-device rootkit campaign is exploiting CVE-2025-20352 and a modified CVE-2017-3881 Telnet flaw to gain persistent, unauthorized access on exposed de...
Cisco network-device rootkit campaign
CampaignAbout this happening: A Cisco network-device rootkit campaign is exploiting CVE-2025-20352 and a modified CVE-2017-3881 Telnet flaw to gain persistent, unauthorized access on exposed de...
Operation Zero Disco Cisco IOS/IOS XE rootkit campaign
Campaign
H score42
First: 16.10.2025 14:38
Last: 16.10.2025 14:38
Sources 1
About this happening:
A new campaign dubbed Operation Zero Disco exploited CVE-2025-20352 against Cisco IOS Software and IOS XE Software, enabling Linux rootkits and persistent...
Operation Zero Disco Cisco IOS/IOS XE rootkit campaign
CampaignAbout this happening: A new campaign dubbed Operation Zero Disco exploited CVE-2025-20352 against Cisco IOS Software and IOS XE Software, enabling Linux rootkits and persistent...
Timeline
-
20.08.2025 18:59 3 articles · 10mo ago
Static Tundra exploits Cisco Smart Install flaw CVE-2018-0171
Initial DisclosureCisco Talos and the FBI described ongoing exploitation of CVE-2018-0171 in Cisco IOS Software and Cisco IOS XE software, where a Russian FSB-linked group known as Static Tundra used Smart Install abuse to gain persistent access to unpatched and often end-of-life network devices. The activity targeted telecommunications, higher education, and manufacturing organizations across North America, Asia, Africa, and Europe, and Cisco advised customers to apply the fixed release for CVE-2018-0171 or disable Smart Install if patching is not possible.
Show sources
- FBI Warns FSB-Linked Hackers Exploiting Unpatched Cisco Devices for Cyber Espionage — thehackernews.com — 20.08.2025 18:59
- FBI, Cisco Warn of Russian Attacks on 7-Year-Old Flaw — www.darkreading.com — 20.08.2025 22:39
- US and allies warn of Russian critical infrastructure attacks — www.bleepingcomputer.com — 13.07.2026 12:32
-
20.08.2025 18:59 3 articles · 10mo ago
Static Tundra exploits Cisco Smart Install flaw CVE-2018-0171
Initial DisclosureCisco Talos and the FBI described ongoing exploitation of CVE-2018-0171 in Cisco IOS Software and Cisco IOS XE software, where a Russian FSB-linked group known as Static Tundra used Smart Install abuse to gain persistent access to unpatched and often end-of-life network devices. The activity targeted telecommunications, higher education, and manufacturing organizations across North America, Asia, Africa, and Europe, and Cisco advised customers to apply the fixed release for CVE-2018-0171 or disable Smart Install if patching is not possible.
Show sources
- FBI Warns FSB-Linked Hackers Exploiting Unpatched Cisco Devices for Cyber Espionage — thehackernews.com — 20.08.2025 18:59
- FBI, Cisco Warn of Russian Attacks on 7-Year-Old Flaw — www.darkreading.com — 20.08.2025 22:39
- US and allies warn of Russian critical infrastructure attacks — www.bleepingcomputer.com — 13.07.2026 12:32