58

Maximum-security Cisco vulnerability was patched Oct. 2023 and exploited Feb. 2025.

you are viewing a single comment's thread
view the rest of the comments
[-] Eyekaytee@aussie.zone 7 points 1 week ago* (last edited 1 week ago)

The hackers exploited CVE-2023-20198 to retrieve running configuration files from the devices and modified at least one of the files to create a GRE tunnel allowing traffic collection from the network the devices were connected to.

tbf they've been patched for ages and/or you can just turn the http web interface off, it's 2 lines of config that takes 30 seconds to apply

We were alerted on the day and had a fix rolled out by end of day on hundreds of routers, this is a bit embarrassing for the canadian telcom tbh

this post was submitted on 23 Jun 2025
58 points (100.0% liked)

Cybersecurity

7702 readers
110 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS