Cisco ASA 0-Day RCE Flaw Actively Exploited in the Wild
A critical zero-day vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software is being actively exploited.
A critical zero-day vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software is being actively exploited.
Identified as CVE-2025-20333 , this remote code execution flaw allows an authenticated attacker to execute arbitrary code as root on affected devices. Cisco issued an advisory on Tue, Sep 25, 2025, urging users to update immediately to a fixed software release, as no workaround exists.
CVE ID Severity CVSS 3.1 Score CWE
CVE-2025-20333 Critical 9.9 CWE-120
CVE-2025-20362 Medium 6.5 CWE-862
Identified as CVE-2025-20333 , this remote code execution flaw allows an authenticated attacker to execute arbitrary code as root on affected devices.
The vulnerability is located in the VPN web server component of ASA and FTD software, resulting from improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN credentials can send specially crafted requests to the VPN web portal, leading to root privilege escalation and full system compromise.
Another reported medium-severity flaw, CVE-2025-20362, allows unauthenticated attackers to access restricted URL endpoints without proper access checks. While this does not result in code execution, it compromises access controls and could facilitate further attacks.
Affected devices include ASA or FTD systems running a vulnerable release with webvpn or AnyConnect IKEv2 remote access enabled. Specific configurations that open SSL listen sockets, such as crypto ikev2 enable <interface> client-services port <port_numbers> and webvpn enable <interface> , are vulnerable. Cisco Secure Firewall Management Center (FMC) and Device Manager (FDM) configurations enabling remote access VPN also expose FTD devices.
Cisco confirmed that Secure FMC Software is not affected. Users should utilize the Cisco Software Checker to identify affected versions and determine the first fixed release. Upgrade guidance and fixed release numbers are available in the advisory's Fixed Software section. There are no workarounds that fully mitigate these vulnerabilities.
After updating, it is advised to review threat detection settings for VPN services to prevent brute-force login attempts, client initiation attacks, and invalid service connections. Detailed instructions are provided in the Cisco Secure Firewall ASA CLI Configuration Guide under "Configure Threat Detection for VPN Services."
The Cisco PSIRT is tracking active exploitation attempts of CVE-2025-20333 and recommends rapid patching. The vulnerability was discovered during a Cisco TAC support case and is currently being used in the wild. It is crucial for security teams to prioritize patching ASA and FTD devices to prevent potential full-system takeover.
Based on reporting by GBHackers.
