logo

Cisco IOS XE Zero-Day CVE-2023-20198 Hack Revealed

ID: 12f44868-52b6-507b-a43e-ec8f71f3b918

STIX ID: report--12f44868-52b6-507b-a43e-ec8f71f3b918

Feed Name: Cyble Blog

Threat Score
92/100

Date Published: 2026-03-18

Date Updated: 2026-07-17

...
...

This report describes active exploitation of CVE-2023-20198, a critical zero-day in the Cisco IOS XE web UI (CVSS 10.0) that allows unauthenticated remote attackers to create privileged accounts and deploy a Lua implant enabling arbitrary command execution. Cisco and Cyble observed exploitation in the wild, documented IoCs (malicious IPs, POST requests with "menu"/"logon_hash" parameters), and recommend disabling the HTTP server feature (no ip http server / no ip http secure-server), applying access controls, and monitoring logs; Snort rules and scanning tools are also provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.