CVE-2018-0171Active Exploitation(cisco / ios)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch cisco ios systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-20CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ios

Threat summary

  • Active exploitation appears in 8 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • Active exploitation reported across 8 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • General: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-07-14); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
ios

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 5d
01345Mentions · 2026-01-27: 1Mentions · 2026-07-13: 1Mentions · 2026-07-14: 5Mentions · 2026-07-16: 1Mentions · 2026-07-17: 1Active Exploitation · 2026-01-27: 1Active Exploitation · 2026-07-13: 1Active Exploitation · 2026-07-14: 4Active Exploitation · 2026-07-16: 1Active Exploitation · 2026-07-17: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-07-13: 1Patch / Workaround · 2026-07-14: 1Technical Details · 2026-01-27: 1Technical Details · 2026-07-13: 1Technical Details · 2026-07-14: 301-2707-1307-1407-1607-17
Signal classification2 categories
Active Exploitation
888.9%
General
111.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-01-271
Active Exploitation1
2026-07-131
Active Exploitation1
2026-07-145
Active Exploitation4General1
2026-07-161
Active Exploitation1
2026-07-171
Active Exploitation1
Full discourse9 posts
  • CISA Cyber@CISACyber
    General

    Our joint advisory with @NSACyber & partners details TTPs Russian cyber actors are using to target routers & network devices in #CriticalInfrastructure sectors, including exploitation of Cisco vulnerabilities CVE-2018-0171 & CVE-2008-4128. More info: 🔗https://go.dhs.gov/5QP https://t.co/tUnLO9fh5E

    Post summary

    The advisory outlines tactics used by Russian actors targeting Cisco routers via CVE-2018-0171 and CVE-2008-4128, but it does not provide PoC, exploit code, patch info, or evidence of active exploitation.

    31402087.1K
    302.1K followersView on X
  • Shanaka Anslem Perera ⚡@shanaka86
    Active Exploitation

    You are touching the third rail. The documented kill chain … CVE-2023-20198: Perfect 10.0 severity score. Creates admin accounts remotely. No authentication needed. CVE-2023-20273: Elevates to root access. CVE-2018-0171: Patched SEVEN YEARS AGO. Still exploited because telecom infrastructure hadn’t updated since 2018. But here’s what should concern everyone: The malware, called Demodex, operates at KERNEL level. Below the operating system. It hooks into system calls to hide itself. When admins run diagnostics, the rootkit filters what they can see. You look for the infection. The infection decides what you find. It survives reboots. It survives reimaging. It survives patches. Cisco Talos documented one network compromised for 3+ years. CISA officially states they “cannot say with certainty” it’s been removed. You know what does remove it? Physical hardware replacement. That’s not a software problem. That’s an architecture problem. And you’re right to ask whether the architecture was the point all along.

    Post summary

    The post highlights severe vulnerabilities being actively exploited via a kernel‑level rootkit that persists through reboots and patches, underscoring that hardware replacement is only effective way to eradicate the threat.

    160143684
    148.0K followersView on X
  • CTI Traffic@CTITraffic
    Active Exploitation

    Joint: FSB Center 16 (Berserk Bear) is scanning for default SNMP community strings and pulling router configs, creds included, via TFTP. Occasional Smart Install / CVE-2018-0171 exploitation. Opportunistic and global. https://www.ic3.gov/CSA/2026/260713.pdf

    Post summary

    FSB Center 16 (Berserk Bear) is actively exploiting CVE-2018-0171 via Smart Install, but the attacks are opportunistic and occasional.

    03052357
    188 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Russian 🇷🇺 FSB Center 16 (Berserk Bear, Dragonfly, Static Tundra) targets routers via SNMP default credentials and CVE-2018-0171 to steal configs via TFTP. #DFIR_Radar https://t.co/Dr6AYZGpPP

    Post summary

    Russian FSB Center 16 is actively exploiting CVE‑2018‑0171 on routers using SNMP default credentials to exfiltrate configuration files via TFTP.

    10001158
    1.8K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    FSB Center 16 exploited weak SNMP configurations and CVE-2018-0171 to compromise routers across defense, energy, and healthcare sectors. Attackers mapped internal networks and established persistent C2 channels for data exfiltration. Runtime segmentation helps contain such lateral movement after initial compromise. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/weak-security-fuel-russian-cyberattacks-2026

    Post summary

    FSB Center 16 leveraged CVE‑2018‑0171 to compromise routers in defense, energy, and healthcare sectors, mapping internal networks and establishing persistent C2 channels for data exfiltration.

    0000049
    1.9K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Russian FSB Center 16 actors exploited default SNMP credentials and CVE-2018-0171 to compromise critical infrastructure routers. Once inside, they used compromised devices to proxy traffic and move laterally across networks. Runtime segmentation could have limited their ability to pivot between internal systems. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/improve-router-hygiene-to-protect-against-russian-state-sponsored-targeting-2026

    Post summary

    Russian FSB actors actively exploited default SNMP credentials and CVE-2018-0171 on critical infrastructure routers, using the compromised devices to pivot and move laterally across networks.

    0000040
    1.9K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Active Exploitation

    🚨 NSA ve 17 ülkenin siber güvenlik kurumları, Rus devlet destekli hackerların Cisco router ve switch'leri hedef almaya devam ettiği konusunda uyardı. Özellikle CVE-2018-0171 (CVSS 9.8) üzerinden Cisco Smart Install özelliği istismar ediliyor. Kurumlara Smart Install'ı devre dışı bırakmaları, cihazları güncellemeleri ve temel ağ güvenliği önlemlerini uygulamaları tavsiye edildi.

    Post summary

    NSA warns that Russian attackers are actively exploiting CVE‑2018‑0171 on Cisco routers and switches via Smart Install, urging users to disable the feature and apply patches.

    00000162
    1.2K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows FSB Center 16 exploiting default SNMP credentials and CVE-2018-0171 to compromise critical infrastructure routers. Attackers moved laterally across networks, exfiltrating config files via TFTP. Runtime segmentation could help limit blast radius in such network-level compromises. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/us-and-allies-warn-of-russian-critical-infrastructure-attacks-2026

    Post summary

    The post reports that FSB operatives are exploiting CVE‑2018‑0171 and default SNMP credentials to hijack critical infrastructure routers, moving laterally and exfiltrating config files via TFTP, while suggesting runtime segmentation as a mitigation.

    0000054
    1.9K followersView on X
  • TECHEPAGES@techepages
    Active Exploitation

    🚨 NSA: disable Cisco Smart Install NOW. Russia's FSB Center 16 is hijacking routers. 🔵 CVE-2018-0171 – CVSS 9.8, unauth RCE 🔵 TCP port 4786 abused 🔵 Defense, energy & healthcare hit 🔵 Fix: SNMPv3, block TFTP/SMI Eight years after disclosure, CVE-2018-0171 continues to expose critical infrastructure. Configuration discipline closes the door.

    Post summary

    The post reports that Russia's FSB is actively exploiting CVE‑2018‑0171 in critical infrastructure, while noting the patch/mitigation steps of SNMPv3 and blocking TFTP/SMI.

    0000057
    19 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSciscoios15.2\(5\)e--

Explore more