HomeSecurityNew zero-day vulnerability in Cisco firewall software

New zero-day vulnerability in Cisco firewall software

A critical zero-day vulnerability in some Cisco Systems firewalls must be patched immediately, U.S. and U.K. government cybersecurity authorities warned Thursday. They said exploits of the vulnerability are part of ongoing attacks on these and other network perimeter devices.

See also: Hackers exploit zero-day vulnerability in Cisco IOS

Cisco

The UK’s National Cyber ​​Security Centre (NCSC) called Cisco’s notification a “significant update” on a malicious campaign against perimeter network devices that was revealed last year and dubbed ArcaneDoor. And the US Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent directive ordering federal departments to identify, analyze and mitigate potential breaches.

The new vulnerability, CVE-2025-20363, is caused by improper user-supplied input validation in HTTP requests, Cisco said. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web service on an affected device after obtaining additional system information, overcoming mitigating exploits, or both.

A successful exploit could allow an attacker to execute arbitrary code as root, which could lead to a complete compromise of the device. Affected devices are devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) software , Cisco Secure Firewall Threat Defense (FTD) software , as well as devices running Cisco IOS, IOS XE , and IOS XR software .

See also: Cisco ASA: Hackers exploit vulnerabilities in 25,000 IPs

New zero-day vulnerability in Cisco firewall software

There are two attack scenarios: an unauthenticated, remote attacker who logs into devices running Cisco ASA and FTD with one or more vulnerable configurations could execute arbitrary code; an authenticated, remote attacker who logs into devices running Cisco IOS, IOS XE , or IOS XR with low user privileges could execute arbitrary code on an affected Cisco device.

However, note that devices running IOS or IOS XE are only affected if they have Remote Access SSL VPN. Devices running IOS XR are only affected if they are running on Cisco ASR 9001 with the HTTP server enabled.

Cisco has released software updates that address this vulnerability and strongly recommends that customers quickly upgrade to a fixed software version. There are no workarounds that address this issue.

Cisco also said Thursday that it had found new activity specifically targeting the ASA 5500-X with two new vulnerabilities: CVE-2025-20333, CVE-2025-20362, and CVE-2025-20363. In a report, the company said that in analyzing confirmed compromised devices, it found that sometimes the attacker modified the ROMMON on Cisco devices. This firmware acts as a low-level bootloader and recovery tool that initializes the hardware and loads the main operating system. Its modification allows the attacker to maintain persistence across reboots and software upgrades.

See also: Cisco Nexus 3000 and 9000 Series: Vulnerability allows DoS attacks

New zero-day vulnerability in Cisco firewall software

Thursday's warning of critical vulnerabilities in Cisco products follows other recent alerts, noting that several other critical vulnerabilities have been identified in Cisco products this summer. CSOs should implement a zero-trust architecture, he said, especially for source monitoring and apply product updates according to the risk they pose to your organization.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS