Cisco has disclosed a critical vulnerability in SD-WAN Manager that attackers have already exploited in zero-day attacks to gain root-level access to affected systems. The company confirmed that threat actors targeted the flaw before a security update became available, increasing the urgency for organizations running vulnerable deployments.

Tracked as CVE-2025-20337, the vulnerability affects Cisco SD-WAN Manager, formerly known as vManage. Successful exploitation allows an authenticated attacker to elevate privileges and execute actions with root permissions on compromised devices.

Cisco released security updates and urged customers to install them as soon as possible.

Attackers Gained Root Access

According to Cisco, the vulnerability stems from improper validation within the affected software. An attacker with valid credentials can exploit the flaw to execute arbitrary commands and obtain root-level control over the system.

Root access gives attackers extensive control over a device. Once they gain those privileges, they can modify configurations, deploy additional payloads, create new accounts, and move deeper into a network environment.

Cisco stated that attackers actively exploited the vulnerability in real-world attacks before the company published a patch.

The disclosure places the flaw among a growing number of enterprise vulnerabilities that organizations have had to address while attacks were already underway.

Organizations Face Increased Risk

SD-WAN platforms often occupy critical positions within enterprise networks. They help manage connectivity between offices, cloud services, and data centers. As a result, successful compromises can provide attackers with valuable access to corporate infrastructure.

Security teams frequently prioritize SD-WAN vulnerabilities because attackers can use compromised management platforms to affect multiple network locations through a single point of control.

Organizations that delay patching may expose critical network management systems to attackers seeking elevated privileges.

Cisco has not publicly identified the threat actors responsible for the attacks, but the company confirmed that exploitation occurred in the wild.

Security Updates Are Available

Cisco released patches that address the vulnerability and recommended that customers update affected systems immediately. The company also advised administrators to review logs and investigate signs of unauthorized activity.

Organizations should verify that only trusted users maintain access to SD-WAN management systems and ensure that administrative credentials remain protected.

Security teams should also monitor privileged accounts and review configuration changes that occurred before patch deployment.

These steps can help identify potential compromise attempts and reduce the risk of further exploitation.

Conclusion

The Cisco SD-WAN flaw highlights the continuing threat posed by vulnerabilities that attackers exploit before vendors release fixes. Cisco confirmed that threat actors used CVE-2025-20337 in zero-day attacks to gain root access to vulnerable systems. Organizations running affected SD-WAN Manager deployments should apply available patches quickly and review their environments for signs of compromise.


0 responses to “Cisco SD-WAN Flaw Exploited in Zero-Day Attacks”