Junglewise Threat Intelligence

CVE-2025-20333: Cisco ASA and FTD buffer overflow in VPN web server

CVE-2025-20333 · Severity: critical · CVSS 9.9 · Exploited in the wild · Published 2025-09-25

Executive brief

Cisco Secure Firewall appliances, which are used to protect corporate networks and provide secure remote access (VPN), contain a critical security flaw. An attacker with valid VPN credentials can exploit this vulnerability to take full control of the firewall device. This could lead to a complete network compromise, data theft, or a total shutdown of secure remote access services.

Technical details

A classic buffer overflow (CWE-120) exists in the VPN web server component of Cisco ASA and FTD software due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials can exploit this by sending crafted HTTP requests to the affected device. Successful exploitation allows for remote code execution (RCE) as the root user, leading to full system compromise. This vulnerability is notable for being exploited in the wild and can be chained with other vulnerabilities like CVE-2025-20362. Cisco has released software updates to address these issues.

Affected products

  • Cisco Adaptive Security Appliance (ASA) Software 9.12 through 9.22.1.3 (specific ranges apply)
  • Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0 through 7.6.0 (specific ranges apply)

Timeline

  • 2025-09-25: disclosed
  • 2025-09-25: advisory
  • 2025-09-25: kev added: Added to CISA KEV due to active exploitation.
  • 2025-09-25: exploited

Related threats