CVE detail
CVE-2018-0171
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 2
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
36 source links · newest first
- US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT GroupsSecurity Affairs
eb portals to manage network devices.” Russia-linked threat actors have also exploited known vulnerabilities, including CVE-2018-0171 and CVE-2008-4128 , to compromise network devices. Their techniques overlap with other threat groups, such as Salt Typhoon . Network defenders should strengthen router security by disabling Cisco Smart Install, replacin
newssecurityaffairs.comJul 15, 2026, 6:59 PM (CVEs) in Cisco devices, as well as in the Cisco’s Smart Install (SMI) tool. Actors have exploited, at the very least, CVE-2018-0171 (published in 2018) and CVE-2008-4128 (published in 2008), according to the bulletin. Both of these targeted Cisco routers , giving remote, unauthenticated attackers the ability to execute arbitrary code, take unauthori
newswww.csoonline.comJul 14, 2026, 1:49 AMnetwork devices. The actors previously exploited at least the following CVEs [ T1584.008 , T1588.005 , T1190 , T1068 ]: CVE-2018-0171 CVE-2008-4128 13 Many of these TTPs overlap with activity by other malicious cyber actors, such as Salt Typhoon . Even though this CSA focuses on Russian FSB Center 16 cyber activity, the mitigations below should detect
governmentwww.cisa.govJul 13, 2026, 12:00 PM- Russian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory WarnsInfosecurity Magazine
ommon vulnerabilities and exposures (CVEs) in Cisco devices. In 2025, Cisco warned that a seven-year-old vulnerability (CVE-2018-0171) in the Smart Install feature of unpatched, often end-of-life Cisco devices, was being exploited by Center 16/Static Tundra. Customers were urged to apply the patch for CVE-2018-0171 or to disable Smart Install if patch
newswww.infosecurity-magazine.comJul 13, 2026, 10:40 AM US offers $10M for Russian FSB officers Tyukov, Gavrilov & Akulov, accused of attacking US critical infrastructure and over 500 energy firms worldwide. The US Department of State is offering up to $10M for info on FSB officers Pavel Aleksandrovich Akulov, Mikhail Mikhailovich Gavrilov, and Marat Valeryevich Tyukov, accused of hacking US infrastructure and over […]
newssecurityaffairs.comSep 4, 2025, 7:03 PMGovernment intelligence and cybersecurity agencies from 13 countries have released a joint advisory detailing the techniques used by Salt Typhoon, a Chinese state-sponsored APT group that has targeted telecommunications, government, transportation, lodging and military infrastructure networks from around the world. The agencies have linked Salt Typhoon’s activities to multiple Chinese entities, including three technology companies […]
newswww.csoonline.comAug 28, 2025, 11:47 PMChina-linked APT ‘Salt Typhoon’ exploited known router flaws to maintain persistent access across telecom, government, and military networks, giving Beijing’s intelligence services global surveillance reach.
newswww.securityweek.comAug 28, 2025, 1:56 PM- NSA, NCSC, and allies detailed TTPs associated with Chinese APT actors targeting critical infrastructure OrgsSecurity Affairs
NSA and allies warn that Chinese APT actors, including Salt Typhoon, are targeting critical infrastructure worldwide. The U.S. National Security Agency (NSA), the UK’s National Cyber Security Centre (NCSC), and allies warn Chinese APT actors, linked to Salt Typhoon, are targeting global telecom, government, transport, lodging, and military sectors. “The National Security Agency (NSA) and […]
newssecurityaffairs.comAug 28, 2025, 10:47 AM - 25th August – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 25th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES US pharmaceutical company Inotiv has experienced a ransomware attack that resulted in the unauthorized access and encryption of certain systems and data. The Qilin ransomware gang claimed responsibility and alleged the theft […]
vendorresearch.checkpoint.comAug 25, 2025, 11:03 AM - Week in review: Covertly connected and insecure Android VPN apps, Apple fixes exploited zero-dayHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Android VPN apps used by millions are covertly connected AND insecure Three families of Android VPN apps, with a combined 700 million-plus Google Play downloads, are secretly linked, according to a group of researchers from Arizona State University and Citizen Lab. Apple fixes zero-day vulnerability exploited in “extremely sophisticated attack” (CVE-2025-43300) Apple has fixed yet another vulnerability (CVE-2025-43300) that has … More →
newswww.helpnetsecurity.comAug 24, 2025, 8:00 AM A threat group linked to the Russian Federal Security Service’s (FSB) Center 16 unit has been compromising unpatched and end-of-life Cisco networking devices via an old vulnerability (CVE-2018-0171), the FBI and Cisco warned on Wednesday. “Primary targets include organizations in telecommunications, higher education and manufacturing sectors across North America, Asia, Africa and Europe, with victims selected based on their strategic interest to the Russian government,” Cisco Talos researchers noted. “In the past year, the FBI … More →
newswww.helpnetsecurity.comAug 21, 2025, 3:00 PMRussian state-sponsored cyber actors linked to the Federal Security Service (FSB) conducted a decade-long espionage campaign that compromised thousands of enterprise network devices across critical sectors worldwide, according to an FBI advisory. The threat actor, designated “Static Tundra” by Cisco Talos and previously known as “Berserk Bear” and “Dragonfly,” systematically exploited CVE-2018-0171, a six-year-old vulnerability […]
newswww.csoonline.comAug 21, 2025, 12:16 PMRussian state-sponsored hackers tracked as Static Tundra continue to target Cisco devices affected by CVE-2018-0171.
newswww.securityweek.comAug 21, 2025, 11:10 AMFBI warns FSB-linked group Static Tundra is exploiting a 7-year-old Cisco IOS/IOS XE flaw to gain persistent access for cyber espionage. The FBI warns that Russia-linked threat actor Static Tundra exploits Simple Network Management Protocol (SNMP) and end-of-life networking devices running an unpatched vulnerability (CVE-2018-0171) in Cisco Smart Install (SMI) to target organizations in the […]
newssecurityaffairs.comAug 21, 2025, 7:51 AM- Salt Typhoon hacked the US National Guard for 9 months, and accessed networks in every stateCSO Online
Chinese-backed APT group Salt Typhoon extensively compromised a US state’s Army National Guard network for nine months, stealing sensitive military data and gaining access to networks in every other US state and at least four territories, according to a Department of Homeland Security memo that warned the breach could facilitate attacks on critical infrastructure nationwide. […]
newswww.csoonline.comJul 16, 2025, 11:57 AM - China’s Salt Typhoon Hacked US National GuardSecurityWeek
Chinese hacking group Salt Typhoon targeted a National Guard unit’s network and tapped into communications with other units.
newswww.securityweek.comJul 16, 2025, 9:20 AM - GreyNoise Observes Active Exploitation of Cisco Vulnerabilities Tied to Salt Typhoon AttacksGreyNoise
GreyNoise has observed exploitation attempts targeting two Cisco vulnerabilities, CVE-2023-20198 and CVE-2018-0171. CVE-2023-20198 is being actively exploited by over 110 malicious IPs, primarily from Bulgaria, Brazil, and Singapore, while CVE-2018-0171 has seen exploitation attempts from two malicious IPs traced t
vendorwww.greynoise.ioFeb 24, 2025, 12:00 AM Cisco Talos observed Chinese hackers pivoting from a compromised device operated by one telecom to target a device in another telecom.
newswww.securityweek.comFeb 21, 2025, 2:54 PMChina-linked cyber espionage group Salt Typhoon uses custom malware JumbledPath to on spy U.S. telecom providers. Cisco Talos researchers reported that China-linked APT group Salt Typhoon uses a custom-built utility, dubbed JumbledPath, to spy on network traffic of U.S. telecommunication providers. China-linked APT group Salt Typhoon (also known as FamousSparrow and GhostEmperor) and has been active since at least 2019 and […]
newssecurityaffairs.comFeb 20, 2025, 11:17 PMIT giant Cisco is warning of threat actors exploiting many old vulnerabilities in attacks in the wild. Cisco has updated multiple security advisories to warn of the active exploitation of several old vulnerabilities impacting its products. The bugs, some of which are rated as ‘critical’ severity, impact Cisco IOS, NX-OS, and HyperFlex software. Below are […]
newssecurityaffairs.comDec 19, 2022, 9:07 PMCisco has updated multiple security advisories to warn of the malicious exploitation of severe vulnerabilities impacting its networking devices. Many of the bugs, which carry severity ratings of ‘critical’ or ‘high’, have been addressed 4-5 years ago, but organizations that haven’t patched their devices continue to be impacted.
newswww.securityweek.comDec 19, 2022, 12:53 PMSeveral US government agencies have issued a joint cybersecurity advisory to provide information on the techniques and tactics that China-linked threat actors have been using to compromise telecom companies and network services providers.
newswww.securityweek.comJun 9, 2022, 1:00 PMChina-linked threat actors have breached telecommunications companies and network service providers to spy on the traffic and steal data. US NSA, CISA, and the FBI published a joint cybersecurity advisory to warn that China-linked threat actors have breached telecommunications companies and network service providers. The nation-state actors exploit publicly known vulnerabilities to compromise the target […]
newssecurityaffairs.comJun 8, 2022, 9:53 AMWhich is more valuable to you; the ability to identify a problem, or the ability to solve the problem? There is a plethora of vulnerability scanning tools that do a decent job identifying vulnerabilities. Unfortunately, those tools rarely discern the possible from the exploitable.
exploithorizon3.aiFeb 11, 2022, 5:08 PM- Rockwell Automation Allen-Bradley Stratix and ArmorStratix switches are exposed to hack due to Cisco IOS flawsSecurity Affairs
Rockwell Automation is warning that its Allen-Bradley Stratix and ArmorStratix industrial switches are exposed to hack due to security vulnerabilities in Cisco IOS. According to Rockwell Automation, eight flaws recently discovered recently in Cisco IOS are affecting its products which are used in many sectors, including the critical manufacturing and energy. The list of flaws includes […]
newssecurityaffairs.comApr 19, 2018, 8:05 PM Cisco informed customers on Wednesday that it has patched critical vulnerabilities in WebEx and UCS Director, along with nine high severity flaws in StarOS, IOS XR, Firepower and ASA products.
newswww.securityweek.comApr 19, 2018, 12:55 PMRockwell Automation informed customers this week that its Allen-Bradley Stratix and ArmorStratix industrial switches are exposed to remote attacks due to vulnerabilities in Cisco’s IOS software.
newswww.securityweek.comApr 18, 2018, 3:13 PMA joint technical alert issued on Monday by the United States and the United Kingdom details how cyberspies believed to be working for the Russian government have abused various networking protocols to breach organizations.
newswww.securityweek.comApr 17, 2018, 7:17 AM- Security Affairs newsletter Round 158 – News of the weekSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that my new book, “Digging in the Deep Web” is online Kindle Edition Paper Copy Once again thank you! · ATMJackpot, a new strain of ATM Malware discovered by experts · Auth0 authentication […]
newssecurityaffairs.comApr 15, 2018, 8:46 AM - Vigilante hackers strike Russia and Iran Networks exploiting Cisco CVE-2018-0171 flawSecurity Affairs
Last week, the hacking crew “JHT” launched a hacking campaign exploiting Cisco CVE-2018-0171 flaw against network infrastructure in Russia and Iran. Last week, the hacking crew “JHT” launched a hacking campaign against CISCO devices in Russian and Iranian networks. The hackers exploited the Cisco CVE-2018-0171 Smart Install to reset the routers to the startup-config and reboot […]
newssecurityaffairs.comApr 9, 2018, 5:41 AM A significant number of Cisco switches located in Iran and Russia have been hijacked in what appears to be a hacktivist campaign conducted in protest of election-related hacking. However, it’s uncertain if the attacks involve a recently disclosed vulnerability or simply abuse a method that has been known for more than a year.
newswww.securityweek.comApr 9, 2018, 5:36 AMCisco PSIRT has published a new security advisory for abuse of the Smart Install protocol, the IT giant has identified hundreds of thousands of exposed devices online. Cisco is advising organizations that hackers could target its switches via the Smart Install protocol. The IT giant has identified hundreds of thousands of exposed devices and warned critical infrastructure […]
newssecurityaffairs.comApr 6, 2018, 4:50 AMCisco has advised organizations to ensure that their switches cannot be hacked via the Smart Install protocol. The networking giant has identified hundreds of thousands of exposed devices and warned that critical infrastructure could be at risk.
newswww.securityweek.comApr 5, 2018, 4:37 PM- Critical vulnerability opens Cisco switches to remote attackHelp Net Security
A critical vulnerability affecting many of Cisco’s networking devices could be exploited by unauthenticated, remote attackers to take over vulnerable devices or trigger a reload and crash. The company says that the vulnerability is not actively exploited in the wild, but as information about it and Proof-of-Concept code has now been published network administrators would do well to install the released security updates as soon a possible. About the vulnerability (CVE-2018-0171) The flaw was discovered … More →
newswww.helpnetsecurity.comApr 4, 2018, 3:35 PM Cisco has patched more than 30 vulnerabilities in its IOS software, including a critical remote code execution flaw that exposes hundreds of thousands – possibly millions – of devices to remote attacks launched over the Internet.
newswww.securityweek.comMar 30, 2018, 8:15 AMThis week Cisco patched three critical vulnerabilities affecting its operating system IOS XE, two of them are remote code execution flaws that could be exploited by an attacker to gain full control over vulnerable systems. Cisco March 2018 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication addressed 22 vulnerabilities, 3 of them rated as […]
newssecurityaffairs.comMar 29, 2018, 10:27 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2018-0172CVSS 8.6 · High
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affec…
- CVE-2026-50144CVSS 7.1 · High
ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434e1d844ea0551b880a1cfb079ce1 and earlier, ncnn allows an out…
- CVE-2026-14087CVSS 8.8 · High
Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially exploit heap cor…
- CVE-2026-56340CVSS 8.7 · High
vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default,…
- CVE-2026-45328CVSS 9.3 · Critical
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c…
- CVE-2026-49840CVSS 9.1 · Critical
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwa…