A critical zero-day vulnerability affecting thousands of firewalls is being actively exploited by malicious actors online.
The vulnerability, codenamed CVE-2025-20333, poses an immediate risk to organizations worldwide, with a CVSS score of 9.9, representing one of the most serious security vulnerabilities discovered in enterprise firewall infrastructure this year.
See also: CISA: Requires Cisco to patch zero-day vulnerabilities

According to data from The Shadowserver Foundation, over 48,800 unpatched IP addresses were identified as of September 29, 2025, with the United States having the highest exposure. The vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, specifically targeting the VPN web server component that millions of organizations rely on for remote access capabilities.
The vulnerability results from improper validation of user-supplied data in HTTP(S) requests processed by the VPN web server. Classified as a CWE-120 buffer overflow, the zero-day allows remote attackers with valid credentials to execute arbitrary code with root privileges on affected devices. This level of access essentially provides complete control over the firewall, allowing attackers to modify security policies, intercept network traffic, and permanently install backdoors.
The attack vector requires valid VPN user credentials, which attackers can obtain through various methods, such as credential stuffing, phishing campaigns, or exploiting weak authentication mechanisms. Once verified, attackers can send specially crafted HTTP requests containing malicious payloads that overflow buffers, allowing shellcode execution as the root user.
See also: New zero-day vulnerability in Cisco firewall software

The Cisco Product Security Incident Response Team (PSIRT) has confirmed active exploitation attempts and warns that successful attacks could lead to a complete compromise of the device. The vulnerability affects devices running vulnerable versions of the ASA or FTD software with certain configurations enabled, such as AnyConnect IKEv2 Remote Access, Mobile User Security (MUS) , and SSL VPN services.
The affected configurations include critical business functions that organizations depend on for secure remote access. The severity of the vulnerability is compounded by the fact that Cisco has confirmed that there are no workarounds to mitigate the risk without applying security updates. A secondary vulnerability, CVE-2025-20362 (CVSS 6.5), accompanies the primary vulnerability and allows unauthenticated attackers to access restricted VPN endpoints that should require authentication.
This unauthorized access vulnerability, categorized as CWE-862 (Missing Authorization), can act as a reconnaissance tool for attackers planning more sophisticated attacks. Cisco has released urgent security updates that address both vulnerabilities and strongly recommends that you install them immediately.
See also: Cisco patches vulnerabilities in Nexus Switches

Organizations should prioritize these updates given the active exploitation and critical nature of the affected systems. The company also advises reviewing threat detection configurations for VPN services to strengthen protection against authentication attacks and unauthorized login attempts.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
