cbcvebase.
CVE-2025-20363
published 2025-09-25

CVE-2025-20363: A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software…

PriorityP188critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
7.52%
93.9th percentile
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privileges to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web service on an affected device after obtaining additional information about the system, overcoming exploit mitigations, or both. A successful exploit could allow the attacker to execute arbitrary code as root, which may lead to the complete compromise of the affected device. For more information about this vulnerability, see the Details ["#details"] section of this advisory.

Affected

2817 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance_software>= 9.12 < 9.12.4.729.12.4.72
ciscoadaptive_security_appliance_software>= 9.14 < 9.14.4.289.14.4.28
ciscoadaptive_security_appliance_software>= 9.16 < 9.16.4.849.16.4.84
ciscoadaptive_security_appliance_software>= 9.17.1 < 9.18.4.579.18.4.57
ciscoadaptive_security_appliance_software>= 9.19.1 < 9.19.1.429.19.1.42
ciscoadaptive_security_appliance_software>= 9.20.1 < 9.20.3.169.20.3.16
ciscoadaptive_security_appliance_software>= 9.22 < 9.22.29.22.2
ciscoadaptive_security_appliance_software>= 9.23 < 9.23.1.39.23.1.3
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software
ciscocisco_adaptive_security_appliance_software

Detection & IOCsextracted from sources · hover to see the quote

commanddataset = cisco_asa_raw | alter alert_level = arrayindex(regextract(_raw_log, "\s%.*?(ASA\-[\d])\-[\d]{1,}\:"), 0)
  • CVE-2025-20363 is triggered via crafted HTTP requests to web services; monitor for anomalous HTTP requests targeting Cisco ASA/FTD/IOS/IOS XE/IOS XR web service endpoints, especially from unauthenticated sources.
  • Monitor Cisco ASA 5500-X series devices (without secure boot) for ROMMON modification, which indicates persistence across reboots and software upgrades by the threat actor.
  • LINE VIPER C2 communications occur over WebVPN client authentication sessions (HTTPS) or ICMP with responses over raw TCP; detect anomalous ICMP traffic or raw TCP responses from ASA devices.
  • The vulnerabilities involve URL path-normalization and heap buffer overflow issues in HTTP(S) services; inspect HTTP requests to Cisco ASA/FTD web services for malformed URL paths indicative of path-normalization bypass attempts.
  • Use the Cortex XDR/XSIAM hunting query against the cisco_asa_raw dataset to graph log type volumes over time and identify periods where logging was disabled or disrupted by the threat actor.
  • Attacks specifically targeted Cisco ASA 5500-X Series devices with VPN web services enabled; prioritize monitoring and patching of this device class.
  • ·CVE-2025-20363 affects unauthenticated remote attackers on Cisco ASA and FTD, but requires authentication (low privilege) for Cisco IOS, IOS XE, and IOS XR — detection and prioritization should account for this difference in attack surface.
  • ·Cisco identified CVE-2025-20363 as being at high risk for imminent exploitation (not yet confirmed exploited in the wild as of Sep. 25, 2025), meaning PoC development and secondary exploitation waves are anticipated.

CVSS provenance

nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck9.0CRITICAL
vendor_cisco9.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.