HomeSecurityCisco: Hackers exploit ASA and FTD vulnerability

Cisco: Hackers exploit ASA and FTD vulnerability

Cisco has confirmed that malicious actors are actively exploiting a critical remote code execution (RCE) vulnerability in its Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software.

Cisco ASA and FTD

The vulnerability was first reported on September 25, 2025 and is tracked as CVE-2025-20333. It poses a serious risk to organizations that rely on these firewalls for VPN access. With a CVSS score of 9.9, it allows authorized attackers to execute arbitrary code with root privileges, potentially leading to a complete compromise of the device.

See also: AI Engine: Vulnerability in WordPress plugin puts 100,000 sites at risk

The issue arises from inadequate validation of user-supplied input in the VPN web server's handling of HTTP(S) requests. An attacker with valid VPN credentials could craft malicious requests to trigger the vulnerability, bypassing normal security controls and executing code that could extract data, install malware, or penetrate deeper into networks.

Cisco is revealing a new attack variant that targets unpatched systems, causing unexpected device reboots and denial-of-service (DoS) outages.

See also: Cl0p Ransomware Exploits New 0-Day Vulnerabilities

Cisco: Hackers exploit ASA and FTD vulnerability

Cisco: Critical vulnerability in ASA and FTD

At its core, the CVE-2025-20333 vulnerability exploits a buffer overflow (CWE-120) in the webvpn component, active when certain remote access features. For ASA software, vulnerable configurations include AnyConnect IKEv2 with client services, Mobile User Security (MUS), or basic SSL VPN configurations via commands such as “webvpn enable FTD devices face similar risks through IKEv2 or SSL VPN-enabled to management interfaces, such as the Cisco Secure Firewall Management Center.

Only devices with SSL listen sockets enabled for these features are exposed. Cisco Secure FMC software remains unaffected.

See also: 7 vulnerabilities in GPT-4o and GPT-5 allow 0-Click attacks

Cisco: Hackers exploit ASA and FTD vulnerability

Protection

There are no workarounds for the threat, which means that upgrades are the only defense. Cisco urges immediate application of updates. Users should upgrade to the versions listed in the advisory, such as ASA 9.18.4.19 or FTD 7.4.2. They should also check configurations using “show running-config” to identify reports and monitor for anomalous VPN traffic.

The company links the exploit to broader attacks on firewall platforms, advising layered defenses such as multi-factor authentication and intrusion detection.

As cyber threats evolve, this incident highlights the risks of delayed updates in perimeter security. Organizations that delay are at risk.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS