Skip to content

CVE-2023-20198

CVE

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
October 31, 2025
Last Seen
November 5, 2025
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Cyberattacks exploiting a critical vulnerability in Cisco IOS XE (CVE-2023-20198) continue, with over 150 devices in Australia still infected with the BadCandy webshell as of late October 2025. Despite patches being available for over two years, many devices remain unpatched and vulnerable to re-inf...

Cyberattacks exploiting the critical Cisco IOS XE vulnerability (CVE-2023-20198) continue to affect Australian devices, with over 150 routers and switches still infected with the BADCANDY webshell as of late October 2025. Despite patches being available for over two years, threat actors are actively...

The Australian government has issued a warning about ongoing cyberattacks exploiting CVE-2023-20198, a critical vulnerability in Cisco IOS XE devices. As of late October 2025, over 150 devices in Australia remain compromised with the BadCandy webshell, despite patches being available since October 2...

Public Exploits

Checking GitHub for proof-of-concept code…