Cisco ASA/FTD 0-Day Vulnerability Exploited for Authentication Bypass – PoC Released
Cisco has issued advisories regarding a zero-day exploit chain affecting its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. These vulnerabilities are reportedly being exploited in targeted attacks by…
Cisco has issued advisories regarding a zero-day exploit chain affecting its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. These vulnerabilities are reportedly being exploited in targeted attacks by an unknown threat actor.
The exploit chain involves two vulnerabilities, CVE-2025-20362 and CVE-2025-20333 , which enable unauthenticated remote code execution (RCE) on affected devices. A third vulnerability, CVE-2025-20363 , has also been patched, although only the first two are actively exploited.
The vulnerabilities are associated with the clientless VPN (WebVPN) feature, which permits bypassing authentication and exploiting a memory corruption flaw.
The attack begins with CVE-2025-20362, an authentication bypass vulnerability caused by a path traversal flaw. This allows an unauthenticated, remote attacker to access restricted URL endpoints that normally require authentication. By sending a specially crafted HTTP request, such as CSCOU...CSCOE , attackers can bypass security checks. A successful bypass is indicated by server responses like "CSRF token mismatch" or "Failed to upload file".
These vulnerabilities are reportedly being exploited in targeted attacks by an unknown threat actor.
Following the bypass, attackers exploit CVE-2025-20333, a buffer overflow vulnerability within the WebVPN feature's file upload process. This flaw, classified as CWE-120, occurs in a Lua script that handles file uploads and fails to validate the "boundary" value size in an HTTP request. An attacker can trigger a buffer overflow by sending a request with a boundary string exceeding the allocated 8192-byte buffer.
This memory corruption can be executed via the CSCOEfilesfileaction.html endpoint, which becomes accessible due to the initial authentication bypass.
The combined exploitation of these vulnerabilities results in unauthenticated RCE, potentially giving an attacker full control over the affected Cisco firewall. The exploit has been observed in the wild, causing system crashes and reboots on vulnerable devices.
Cisco ASA and FTD software are compromised when the clientless VPN (WebVPN) portal is enabled. Cisco has released patched software versions, including ASAv version 9.16.4.85, to address these critical vulnerabilities. Administrators are strongly advised to update their systems promptly to mitigate potential exploitation.
Based on reporting by Cyber Security News.
