Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild

A critical zero-day vulnerability, identified as CVE-2025-20333 , is actively being exploited, impacting thousands of Cisco firewalls globally. The vulnerability has a CVSS score of 9.9, indicating its severe threat to enterprise firewall infrastructure.

A critical zero-day vulnerability, identified as CVE-2025-20333 , is actively being exploited, impacting thousands of Cisco firewalls globally. The vulnerability has a CVSS score of 9.9, indicating its severe threat to enterprise firewall infrastructure.

The vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, particularly the VPN web server component. On September 29, 2025, The Shadowserver Foundation identified over 48,800 unpatched IP addresses, with significant exposure in the United States.

Buffer Overflow Vulnerability (CVE-2025-20333)

This vulnerability arises from inadequate validation of user input in HTTP(S) requests handled by the VPN web server. Classified as a CWE-120 buffer overflow, it allows authenticated remote attackers to execute arbitrary code with root privileges on affected devices. This access can lead to complete control over the firewall, enabling modification of security policies, interception of network traffic, and establishment of backdoors.

The attack requires valid VPN user credentials, which can be acquired through methods such as credential stuffing, phishing campaigns, or exploiting weak authentication mechanisms. Attackers, once authenticated, can send specially crafted HTTP requests to execute shellcode in the root user context.

A critical zero-day vulnerability, identified as CVE-2025-20333 , is actively being exploited, impacting thousands of Cisco firewalls globally.
Paige Monroe · Thehackingpost

The vulnerability affects devices running specific configurations of ASA or FTD software, including:

AnyConnect IKEv2 Remote Access with client services enabled Mobile User Security (MUS) implementations SSL VPN deployments

These configurations are critical for secure remote access in enterprise environments. Cisco has confirmed there are no workarounds other than applying security patches.

Advertisement

Missing Authorization Flaw (CVE-2025-20362)

A secondary vulnerability, CVE-2025-20362, also known as CWE-862 (Missing Authorization), has a CVSS score of 6.5. It allows unauthenticated attackers to access restricted VPN endpoints, serving as a reconnaissance tool for more sophisticated attacks.

Cisco has issued emergency security updates to address both vulnerabilities and strongly recommends immediate patching. Organizations are advised to prioritize these updates due to the active exploitation and critical nature of the affected systems. Enhancing threat detection configurations for VPN services is also recommended to protect against authentication attacks and unauthorized connection attempts.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories