{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/net-snmp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:net_snmp:net_snmp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-89147"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Net-SNMP (\u003c= 5.9.5.2)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","network-infrastructure","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Net-SNMP"],"content_html":"\u003cp\u003eNet-SNMP versions through 5.9.5.2 are susceptible to a critical denial of service vulnerability within the SMUX (SNMP Multiplexing) protocol module. The issue originates from the smux_accept() function, which performs an unauthenticated blocking read on incoming connections without implementing a timeout mechanism. Because the primary snmpd process operates in a single-threaded architecture, an attacker can trigger this flaw by establishing a connection to the SMUX listener and intentionally sending no data. This forces the process to block indefinitely while awaiting input, effectively suspending all SNMP monitoring and management capabilities for the target device. This vulnerability presents a high impact to network availability as it allows unauthenticated remote actors to disable monitoring instrumentation without requiring complex payloads or elevated privileges.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a complete denial of service for SNMP management services on the affected system. This disruption prevents administrators from gathering performance telemetry, monitoring device health, or performing remote configuration management. The vulnerability targets any system running Net-SNMP with the SMUX module enabled, impacting enterprise network infrastructure and server environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize upgrading to a version of Net-SNMP where the smux_accept() timeout issue is addressed. Until patching is completed, identify and disable the SMUX protocol on all internet-facing or unauthorized SNMP management endpoints to reduce the attack surface.\u003c/p\u003e\n","date_modified":"2026-09-11T13:13:17Z","date_published":"2026-09-11T13:13:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-net-snmp-smux-dos/","summary":"An unauthenticated denial of service vulnerability in Net-SNMP versions up to 5.9.5.2 allows remote attackers to hang the snmpd process by initiating idle connections to the SMUX module.","title":"Net-SNMP Denial of Service via SMUX Module","url":"https://feed.craftedsignal.io/briefs/2026-09-net-snmp-smux-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Net-SNMP","version":"https://jsonfeed.org/version/1.1"}