Critical Cisco Flaw Lets Remote Attackers Execute Code on Firewalls and Routers
On Fri, Oct 20, 2023, Cisco released a Security Advisory addressing a critical vulnerability in several Cisco platforms that manage HTTP-based communications. This vulnerability, identified as CVE-2025-20363 , results from inadequate validation of…
On Fri, Oct 20, 2023, Cisco released a Security Advisory addressing a critical vulnerability in several Cisco platforms that manage HTTP-based communications. This vulnerability, identified as CVE-2025-20363 , results from inadequate validation of user-supplied input in HTTP requests.
CVE Affected Products Impact CVSS 3.1 Score
CVE-2025-20363 Secure Firewall ASA & FTD with SSL VPN or MUS enabled; IOS/IOS XE with Remote Access SSL VPN; IOS XR (32-bit) on ASR-9001 with HTTP server enabled Full root code execution, total device compromise 9.0
The vulnerability allows attackers to execute arbitrary code as the root user, leading to a complete compromise of the affected device. The flaw affects:
Cisco Secure Firewall ASA and Secure Firewall Threat Defense (FTD) Software Cisco IOS, IOS XE, and IOS XR Software
This vulnerability, identified as CVE-2025-20363 , results from inadequate validation of user-supplied input in HTTP requests.
For ASA and FTD devices, attackers can exploit the vulnerability without authentication, sending crafted requests to SSL-enabled web services. On IOS, IOS XE, and IOS XR platforms, even low-privileged authenticated users can gain root access through this flaw.
Cisco has classified the impact as Critical , with a CVSS 3.1 base score of 9.0, indicating complete compromise of confidentiality, integrity, and availability through a network-based attack without user interaction.
No workarounds are available; only software updates fully mitigate the issue. Affected configurations include webvpn or crypto ssl policy settings on ASA/FTD and IOS/XE, or http server on IOS XR. The advisory provides bug IDs CSCwo18850, CSCwo35704, and CSCwo35779 for tracking purposes.
Customers should verify device configurations and upgrade to the fixed releases specified in the advisory. The Cisco Software Checker tool is available to determine exposure and obtain fixed software versions.
For IOS XR users on 32-bit ASR 9001 platforms, contacting Cisco TAC for SMUs is necessary. There have been no observed public exploits or attacks utilizing CVE-2025-20363.
Apply the fixed software releases for affected firewalls and routers immediately. Use the Cisco Software Checker to confirm platform exposure. Contact Cisco TAC for support if upgrades cannot be performed directly or if lacking a valid service contract.
Failure to address this vulnerability may lead to critical network infrastructure being compromised by remote adversaries. Timely deployment of patches is essential to maintain security across Cisco firewall and routing platforms.
Based on reporting by GBHackers.
