48+ Cisco Firewalls Hit by Actively Exploited 0-Day Vulnerability
Cisco has identified two critical vulnerabilities affecting its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls.
Cisco has identified two critical vulnerabilities affecting its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls.
The vulnerabilities, identified as CVE-2025-20333 and CVE-2025-20362, enable attackers to execute arbitrary code on devices that have not been updated. Cisco's security advisories indicate that exploits for these vulnerabilities are actively being used.
Organizations are advised to review their systems and apply the most recent software updates promptly.
According to Shadowserver's daily report, there are numerous ASA/FTD instances at risk due to these vulnerabilities. As of Fri, Sep 29, 2025, over 48,800 publicly accessible IPs are operating on outdated firewall versions.
The United States is the leading country with exposed hosts, followed by Germany, Brazil, India, and the United Kingdom. These vulnerabilities pose significant risks, as compromised firewalls can lead to unauthorized access, data exfiltration, and potential lateral movement within corporate networks.
Cisco has identified two critical vulnerabilities affecting its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls.
CVE Affected Products Impact Exploit Prerequisites CVSS 3.1 Score
CVE-2025-20333 Cisco ASA and FTD through 9.18.1.17 Remote code execution, full OS control Network access to management interface 9.8
CVE-2025-20362 Cisco ASA and FTD through 9.18.1.17 Privilege escalation, command injection Valid user credentials 9.1
Patch immediately: Download the latest ASA/FTD software from Cisco’s advisory portal and install Maintenance Release 9.18.1.18 or later. Limit management access: Restrict web and API access for ASA/FTD interfaces to trusted IPs only. Harden credentials: Implement multi-factor authentication and enforce strong passwords for all firewall admin accounts. Monitor logs: Regularly check for unusual admin logins, configuration changes, or abnormal traffic patterns. Network segmentation: Ensure critical assets are protected by additional security layers in case a firewall is compromised.
Due to active exploitation and high CVSS scores, these vulnerabilities require immediate attention. Delaying the application of necessary patches could lead to full network compromise and data breaches. Security teams are urged to act swiftly to mitigate these risks.
Based on reporting by GBHackers.
