48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild
A critical zero-day vulnerability, identified as CVE-2025-20333 , is actively being exploited, impacting thousands of Cisco firewalls globally. The vulnerability has a CVSS score of 9.9, indicating its severe threat to enterprise firewall infrastructure.
A critical zero-day vulnerability, identified as CVE-2025-20333 , is actively being exploited, impacting thousands of Cisco firewalls globally. The vulnerability has a CVSS score of 9.9, indicating its severe threat to enterprise firewall infrastructure.
The vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, particularly the VPN web server component. On September 29, 2025, The Shadowserver Foundation identified over 48,800 unpatched IP addresses, with significant exposure in the United States.
Buffer Overflow Vulnerability (CVE-2025-20333)
This vulnerability arises from inadequate validation of user input in HTTP(S) requests handled by the VPN web server. Classified as a CWE-120 buffer overflow, it allows authenticated remote attackers to execute arbitrary code with root privileges on affected devices. This access can lead to complete control over the firewall, enabling modification of security policies, interception of network traffic, and establishment of backdoors.
The attack requires valid VPN user credentials, which can be acquired through methods such as credential stuffing, phishing campaigns, or exploiting weak authentication mechanisms. Attackers, once authenticated, can send specially crafted HTTP requests to execute shellcode in the root user context.
A critical zero-day vulnerability, identified as CVE-2025-20333 , is actively being exploited, impacting thousands of Cisco firewalls globally.
The vulnerability affects devices running specific configurations of ASA or FTD software, including:
AnyConnect IKEv2 Remote Access with client services enabled Mobile User Security (MUS) implementations SSL VPN deployments
These configurations are critical for secure remote access in enterprise environments. Cisco has confirmed there are no workarounds other than applying security patches.
Missing Authorization Flaw (CVE-2025-20362)
A secondary vulnerability, CVE-2025-20362, also known as CWE-862 (Missing Authorization), has a CVSS score of 6.5. It allows unauthenticated attackers to access restricted VPN endpoints, serving as a reconnaissance tool for more sophisticated attacks.
Cisco has issued emergency security updates to address both vulnerabilities and strongly recommends immediate patching. Organizations are advised to prioritize these updates due to the active exploitation and critical nature of the affected systems. Enhancing threat detection configurations for VPN services is also recommended to protect against authentication attacks and unauthorized connection attempts.
Based on reporting by Cyber Security News.
