
In this video, I explain how Cisco Smart Install can leave you and your company vulnerable if it is left on. (Helpful hint: Cisco Smart Install is often on by default, so watch this and then go check your network).
Network admins are surely familiar with Cisco Smart Install – the handy plug-and-play configuration and management feature that offers zero-touch deployments.
And though Cisco is known for security, and the Smart Install feature has some great benefits – such as allowing you to easily deploy network switches in a Cisco environment with no assistance from a network admin – it also can be a security risk if you leave it turned on. Whether by design or default, I find a lot of cases where it’s left on, but none where it’s actually in use at that time. For a penetration tester, that’s a key finding.
Have you checked your network to see if Cisco Smart Install is on. It was, wasn’t it? And, you did turn it off, right?
If so, you closed off a simple but often effective door for hackers.
Raxis is an elite team of professionals who are paid to attack and assess cybersecurity systems. We can help you pinpoint security threats and find ways to remediate them leaving your company more secure than we found it.
Ready to find out how secure your network really is? Reach out to us and let’s discuss your needs and how we can help.

Raxis Research Team
About The Exploit Blog
The Exploit is written by Raxis penetration testers. Every post is a technical writeup from someone who runs engagements for a living, with code, command output, and the reasoning behind each step. Topics include exploit research, vulnerability disclosure, tool development, and the offensive techniques showing up in current client work.
Search The Exploit Blog
Raxis Discovered Vulnerabilities
View the CVEs and bugs that Raxis pentesters have uncovered and submitted.
Blog Categories
- AI
- Careers
- Choosing a Penetration Testing Company
- Exploits
- How To
- In The News
- Injection Attacks
- Just For Fun
- Meet Our Team
- Mobile Apps
- Networks
- Password Cracking
- Patching
- Penetration Testing
- Phishing
- PTaaS
- Raxis Discovered Vulnerabilities
- Raxis In The Community
- Red Team
- Security Recommendations
- Social Engineering
- Tips For Everyone
- Web Apps
- What People Are Saying
- Wireless