CVE-2025-20363
published 2025-09-25CVE-2025-20363: A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software…
PriorityP188critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
7.52%
93.9th percentile
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privileges to execute arbitrary code on an affected device.
This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web service on an affected device after obtaining additional information about the system, overcoming exploit mitigations, or both. A successful exploit could allow the attacker to execute arbitrary code as root, which may lead to the complete compromise of the affected device.
For more information about this vulnerability, see the Details ["#details"] section of this advisory.
Affected
2817 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | >= 9.12 < 9.12.4.72 | 9.12.4.72 |
| cisco | adaptive_security_appliance_software | >= 9.14 < 9.14.4.28 | 9.14.4.28 |
| cisco | adaptive_security_appliance_software | >= 9.16 < 9.16.4.84 | 9.16.4.84 |
| cisco | adaptive_security_appliance_software | >= 9.17.1 < 9.18.4.57 | 9.18.4.57 |
| cisco | adaptive_security_appliance_software | >= 9.19.1 < 9.19.1.42 | 9.19.1.42 |
| cisco | adaptive_security_appliance_software | >= 9.20.1 < 9.20.3.16 | 9.20.3.16 |
| cisco | adaptive_security_appliance_software | >= 9.22 < 9.22.2 | 9.22.2 |
| cisco | adaptive_security_appliance_software | >= 9.23 < 9.23.1.3 | 9.23.1.3 |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commanddataset = cisco_asa_raw | alter alert_level = arrayindex(regextract(_raw_log, "\s%.*?(ASA\-[\d])\-[\d]{1,}\:"), 0)↗
- →CVE-2025-20363 is triggered via crafted HTTP requests to web services; monitor for anomalous HTTP requests targeting Cisco ASA/FTD/IOS/IOS XE/IOS XR web service endpoints, especially from unauthenticated sources. ↗
- →Monitor Cisco ASA 5500-X series devices (without secure boot) for ROMMON modification, which indicates persistence across reboots and software upgrades by the threat actor. ↗
- →LINE VIPER C2 communications occur over WebVPN client authentication sessions (HTTPS) or ICMP with responses over raw TCP; detect anomalous ICMP traffic or raw TCP responses from ASA devices. ↗
- →The vulnerabilities involve URL path-normalization and heap buffer overflow issues in HTTP(S) services; inspect HTTP requests to Cisco ASA/FTD web services for malformed URL paths indicative of path-normalization bypass attempts. ↗
- →Use the Cortex XDR/XSIAM hunting query against the cisco_asa_raw dataset to graph log type volumes over time and identify periods where logging was disabled or disrupted by the threat actor. ↗
- →Attacks specifically targeted Cisco ASA 5500-X Series devices with VPN web services enabled; prioritize monitoring and patching of this device class. ↗
- ·CVE-2025-20363 affects unauthenticated remote attackers on Cisco ASA and FTD, but requires authentication (low privilege) for Cisco IOS, IOS XE, and IOS XR — detection and prioritization should account for this difference in attack surface. ↗
- ·Cisco identified CVE-2025-20363 as being at high risk for imminent exploitation (not yet confirmed exploited in the wild as of Sep. 25, 2025), meaning PoC development and secondary exploitation waves are anticipated. ↗
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck9.0CRITICAL
vendor_cisco9.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8wv4-73v4-qxp2: A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) So
ghsa_unreviewed·2025-09-25
CVE-2025-20363 [CRITICAL] CWE-122 GHSA-8wv4-73v4-qxp2: A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) So
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privileges to execute arbitrary code on an affected device.
This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web service on an affected device after obtaining additional information about the system, overcoming exploit mitigations, or both. A successful exploit could allow
VulnCheck
Cisco IOS XR Heap-based Buffer Overflow
vulncheck·2025·CVSS 9.0
CVE-2025-20363 [CRITICAL] Cisco IOS XR Heap-based Buffer Overflow
Cisco IOS XR Heap-based Buffer Overflow
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privileges to execute arbitrary code on an affected device.
This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web service on an affected device after obtaining additional information about the system, overcoming exploit mitigations, o
Cisco
Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software, and IOS XR Software Web Services Remote Code Execution Vulnerability
vendor_cisco·2025-09-25·CVSS 9.0
CVE-2025-20363 [CRITICAL] CWE-122 Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software, and IOS XR Software Web Services Remote Code Execution Vulnerability
Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software, and IOS XR Software Web Services Remote Code Execution Vulnerability
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privileges to execute arbitrary code on an affected device.
This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sendin
Cisco
Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software, and IOS XR Software Web Services Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20363 Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software, and IOS XR Software Web Services Remote Code Execution Vulnerability
CVE-2025-20363: Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software, and IOS XR Software Web Services Remote Code Execution Vulnerability
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privileges to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerabi
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Cisco: Actively exploited firewall flaws now abused for DoS attacks
blogs_bleepingcomputer·2025-11-07·CVSS 9.9
CVE-2025-20362 [CRITICAL] Cisco: Actively exploited firewall flaws now abused for DoS attacks
## Cisco: Actively exploited firewall flaws now abused for DoS attacks
## Sergiu Gatlan
Cisco warned this week that two vulnerabilities, which have been used in zero-day attacks, are now being exploited to force ASA and FTD firewalls into reboot loops.
The tech giant released security updates on September 25 to address the two security flaws, stating that CVE-2025-20362 enables remote threat actors to access restricted URL endpoints without authentication, while CVE-2025-20333 allows authenticated attackers to gain remote code execution on vulnerable devices.
When chained, these vulnerabilities allow remote, unauthenticated attackers to gain complete control over unpatched systems.
The same day, CISA issued an emergency directive ordering U.S. federal agencies to secure their Cisco fi
Checkpoint
29th September – Threat Intelligence Report
blogs_checkpoint·2025-09-29
CVE-2025-26399 29th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th September, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Stellantis, Automotive maker giant which owns Citroën, FIAT, Jeep, Chrysler, and Peugeot, has suffered a data breach that resulted in exposure of North American customer contact information after attackers accessed a third-party platform tied to its Salesforce environment. ShinyHunters threat actor claims responsibili
Unit42
Threat Insights: Active Exploitation of Cisco ASA Zero Days
blogs_unit42·2025-09-26·CVSS 9.9
[CRITICAL] Threat Insights: Active Exploitation of Cisco ASA Zero Days
## September 2025 Zero-Day Vulnerabilities Affecting Cisco Software
Unit 42 stopped monitoring this threat and updating the brief on Dec. 2, 2025. Please refer to the Cisco website for the latest information.
Cisco has reported that a sophisticated state-sponsored threat actor is actively exploiting multiple zero-day vulnerabilities in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. Cisco identifies this as the same threat actor from a previous campaign they named ArcaneDoor.
This threat actor primarily targets government networks worldwide for data exfiltration. Cisco observed attackers exploiting these newly identified zero-day vulnerabilities while employing advanced evasion techniques to prevent logging and identification of this activity.
The t
Tenable
Cybersecurity Snapshot: CISA Highlights Vulnerability Management Importance in Breach Analysis, as Orgs Are Urged To Patch Cisco Zero-Days
blogs_tenable·2025-09-26
Cybersecurity Snapshot: CISA Highlights Vulnerability Management Importance in Breach Analysis, as Orgs Are Urged To Patch Cisco Zero-Days
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Zscaler
Cisco Firewall and VPN Zero Day Attacks | ThreatLabz
blogs_zscaler·2025-09-26·CVSS 9.9
[CRITICAL] Cisco Firewall and VPN Zero Day Attacks | ThreatLabz
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Unit42
Threat Insights: Active Exploitation of Cisco ASA Zero Days
blogs_unit42·2025-09-26·CVSS 9.9
CVE-2025-20333 [CRITICAL] Threat Insights: Active Exploitation of Cisco ASA Zero Days
Threat Research Center
Insights
General
## Threat Insights: Active Exploitation of Cisco ASA Zero Days
Andy Piazza
Published: September 26, 2025
General
Insights
Cisco
CVE-2025-20333
CVE-2025-20362
CVE-2025-20363
Zero-day
## September 2025 Zero-Day Vulnerabilities Affecting Cisco Software
Unit 42 stopped monitoring this threat and updating the brief on Dec. 2, 2025. Please refer to the Cisco website for the latest information.
Cisco has reported that a sophisticated state-sponsored threat actor is actively exploiting multiple zero-day vulnerabilities in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. Cisco identifies this as the same threat actor from a previous campaign they named ArcaneDoor.
This threat actor primarily targets gove
Bleepingcomputer
CISA orders agencies to patch Cisco flaws exploited in zero-day attacks
blogs_bleepingcomputer·2025-09-25·CVSS 9.9
CVE-2025-20333 [CRITICAL] CISA orders agencies to patch Cisco flaws exploited in zero-day attacks
## CISA orders agencies to patch Cisco flaws exploited in zero-day attacks
## Sergiu Gatlan
CISA has issued a new emergency directive ordering U.S. federal agencies to secure their Cisco firewall devices against two flaws that have been exploited in zero-day attacks.
Emergency Directive 25-03 was issued to Federal Civilian Executive Branch (FCEB) agencies on September 25 and requires them to patch CVE-2025-20333 and CVE-2025-20362 vulnerabilities in Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software.
"The campaign is widespread and involves exploiting zero-day vulnerabilities to gain unauthenticated remote code execution on ASAs, as well as manipulating read-only memory (ROM) to persist through reboot and system upgrade. This activity presents a significant ri
Tenable
CVE-2025-20333, CVE-2025-20362: Cisco Zero-Days Exploited | Tenable®
blogs_tenable·2025-09-25·CVSS 9.9
[CRITICAL] CVE-2025-20333, CVE-2025-20362: Cisco Zero-Days Exploited | Tenable®
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Cisco warns of ASA firewall zero-days exploited in attacks
blogs_bleepingcomputer·2025-09-25·CVSS 9.9
CVE-2025-20333 [CRITICAL] Cisco warns of ASA firewall zero-days exploited in attacks
## Cisco warns of ASA firewall zero-days exploited in attacks
## Sergiu Gatlan
Cisco warned customers today to patch two zero-day vulnerabilities that are actively being exploited in attacks and impact the company's firewall software.
The first one ( CVE-2025-20333 ) allows authenticated, remote attackers to execute arbitrary code on devices running vulnerable Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software, while the second ( CVE-2025-20362 ) enables remote attackers to access restricted URL endpoints without authentication.
"The Cisco Product Security Incident Response Team (PSIRT) is aware of attempted exploitation of this vulnerability," the company warned in security advisories regarding the two zero-day flaws.
"Cisco continues to strongly recommend t
Talos
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
blogs_talos·2024-04-24·CVSS 9.9
CVE-2025-20333 [CRITICAL] ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
## ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
*Update 2025-09-25: Cisco is aware of new activity targeting certain Cisco Adaptive Security Appliances (ASA) 5500-X Series and has released three CVE’s related to the event: CVE-2025-20333 , CVE-2025-20362 and CVE-2025-20363 . The following Snort Rules cover these vulnerabilities: 65340, 46897.
We assess with high confidence this activity is related to same threat actor as ArcaneDoor in 2024.
We strongly recommend that Cisco customers upgrade their devices to the available fixed software and follow guidance in the security advisories.
*Updated 2024-04-25 16:57 GMT with minor wording corrections regarding the targeting of other vendors. ArcaneDoor is a campaign that is the latest example of state-s
Talos
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
blogs_talos·2024-04-24·CVSS 9.9
CVE-2025-20333 [CRITICAL] ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
*Update 2025-09-25: Cisco is aware of new activity targeting certain Cisco Adaptive Security Appliances (ASA) 5500-X Series and has released three CVE’s related to the event: CVE-2025-20333, CVE-2025-20362 and CVE-2025-20363. The following Snort Rules cover these vulnerabilities: 65340, 46897.
We assess with high confidence this activity is related to same threat actor as ArcaneDoor in 2024.
We strongly recommend that Cisco customers upgrade their devices to the available fixed software and follow guidance in the security advisories.
*Updated 2024-04-25 16:57 GMT with minor wording corrections regarding the targeting of other vendors.
ArcaneDoor is a campaign that is the latest example of state-sponsored actors targeting perimeter network devices from multiple vendors. Coveted by these
Recorded Future
September 2025 CVE Landscape
blogs_recorded_future·CVSS 7.2
[HIGH] September 2025 CVE Landscape
# September 2025 CVE Landscape
In September 2025, Recorded Future’s Insikt Group® identified sixteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the eighteen identified in August, with the number of Very Critical vulnerabilities also decreasing (11) month over month.
These vulnerabilities have affected the following vendors: Sudo, Libraesva, Fortra, Cisco, Adminer, Google, Dassault Systèmes, Linux, Android, Sitecore, TP-Link, and Meta Platforms.
September was dominated by flaws in Cisco and TP-Link, which together represented six of the sixteen vulnerabilities. Cisco’s IOS, IOS XE, and Secure Firewall products were affected by flaws, including stack-based and classic buffer overflows (CWE-121, CWE-120) and missing authorization
Recorded Future
September 2025 CVE Landscape
blogs_recorded_future·CVSS 7.2
[HIGH] September 2025 CVE Landscape
## September 2025 CVE Landscape
In September 2025, Recorded Future’s Insikt Group® identified sixteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the eighteen identified in August, with the number of Very Critical vulnerabilities also decreasing (11) month over month.
These vulnerabilities have affected the following vendors: Sudo, Libraesva, Fortra, Cisco, Adminer, Google, Dassault Systèmes, Linux, Android, Sitecore, TP-Link, and Meta Platforms.
September was dominated by flaws in Cisco and TP-Link, which together represented six of the sixteen vulnerabilities. Cisco’s IOS, IOS XE, and Secure Firewall products were affected by flaws, including stack-based and classic buffer overflows (CWE-121, CWE-120) and missing authorizatio
Zscaler
CXO Monthly Roundup, September 2025: Cisco Firewall and VPN vulnerabilities, Shai-Hulud NPM worm emerges, APT37's Rust backdoor, SmokeLoader's additional variant, and COLDRIVER's latest
blogs_zscaler·CVSS 9.9
[CRITICAL] CXO Monthly Roundup, September 2025: Cisco Firewall and VPN vulnerabilities, Shai-Hulud NPM worm emerges, APT37's Rust backdoor, SmokeLoader's additional variant, and COLDRIVER's latest
## CXO Monthly Roundup, September 2025: Cisco Firewall and VPN vulnerabilities, Shai-Hulud NPM worm emerges, APT37's Rust backdoor, SmokeLoader's additional variant, and COLDRIVER's latest campaign, and new discoveries from ThreatLabz
Deepen Desai
Contributor
Zscaler
## Oct 10, 2025
Highlights from the Zscaler ThreatLabz team's September 2025 research.
The CXO Monthly Roundup provides the latest Zscaler ThreatLabz research, alongside insights into other cyber-related subjects that matter to technology executives. This September roundup highlights Cisco Firewall and VPN vulnerabilities, the emergence of the Shai-Hulud NPM worm, APT37's use of a Rust backdoor, new SmokeLoader variants, COLDRIVER's latest campaign, and other key discoveries from ThreatLabz, including malware families li
2025-09-25
Published
Exploited in the wild