CVE-2018-0171
Actively exploited. CVE-2018-0171 is listed in the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03) — exploitation has been observed in the wild, and US federal agencies are required to remediate it under BOD 22-01. Treat patching as urgent.
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2018-0171 is indexed in Exploit-DB, GitHub PoC and Nuclei. Expect opportunistic scanning and exploitation attempts — prioritize remediation.
Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Public Service Announcement of the decade-plus FSB Center 16 cyber activity by providing additional tactics, techniques, and procedures (TTPs) to enable defenders to more fully understand and counter the threat. [ 1 ] This CSA is being released by the following authoring and co-sealing agencies: United States National Security Agency (NSA) United States Cybersecurity and Infrastructure Security Agency (CISA) United States Federal Bureau of Investigation (FBI) United States Department of Defense Cyber Crime Center (DC3) Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre) New Zealand National Cyber Security Centre (NCSC-NZ) United Kingdom National Cyber Security Centre (NCSC-UK) Czech Republic National Cyber and Information Security Agency (NÚKIB) 1 Danish Defence Intelligence Service (DDIS) 2 Estonian Foreign Intelligence Service (EFIS) 3 Estonian Information System Authority (RIA) 4 Finnish Defence Intelligence (FDI) 5 Finnish Security and Intelligence Service (SUPO) 6 French National Cybersecurity Agency (ANSSI) 7 Italian External Intelligence and Security Agency (AISE) 8 Italian Internal Intelligence and Security Agency (AISI) 9 The Military Counterintelligence Service of Poland (SKW) 10 Sweden National Cyber Security Centre (NCSC-SE) 11 The authoring and co-sealing agencies strongly urge device owners and network defenders to take mitigation and
CSIRTS triage
- What
- Russian state-sponsored actors are exploiting poorly configured and vulnerable networking devices.
- Who is affected
- Critical infrastructure sectors with vulnerable networking devices are affected.
- Urgency
- Remediation is urgent due to ongoing exploitation and critical severity.
- Action
- Improve router configurations and security hygiene.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2018-0171
Get an email if CVE-2018-0171 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Exploitation confirmedAlready exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
Exploit availability
Public exploit or proof-of-concept code for CVE-2018-0171 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.
- Exploit-DBA public exploit is published in the Exploit-DB archive.look it up ↗
- GitHub PoCPublic proof-of-concept repositories on GitHub reference this CVE.look it up ↗
- NucleiA nuclei-templates detection/PoC template exists for this CVE.look it up ↗
Advisory coverage (2)
- criticalexploitedImprove Router Hygiene to Protect Against Russian State-Sponsored Targetingcisa · 2026-07-13
- criticalexploitedCVE-2018-0171: Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerabilitycisa-kev · 2021-11-03
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2018-0171)