Junglewise Threat Intelligence

CVE-2025-20362: Cisco Secure Firewall ASA and FTD missing authorization in VPN web server

CVE-2025-20362 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2025-09-25

Executive brief

Cisco Secure Firewall devices, which are used to provide secure remote access and network protection, contain a security flaw in their VPN web server component. An unauthorized attacker can bypass security checks to access restricted areas of the management interface or cause the device to crash and reboot. This vulnerability is actively being exploited in the wild and can lead to a total loss of network connectivity for the organization.

Technical details

A missing authorization vulnerability (CWE-862) exists in the VPN web server of Cisco ASA and FTD software due to improper validation of user-supplied input in HTTP(S) requests. A remote, unauthenticated attacker can exploit this by sending crafted HTTP requests to access restricted URL endpoints related to remote access VPN. Furthermore, a variant of this attack can trigger an unexpected device reload, resulting in a denial-of-service (DoS) condition. This vulnerability has been observed being chained with other flaws and is actively exploited in the wild. Cisco has released software updates to address this issue.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance (ASA)
  • Cisco Secure Firewall Threat Defense (FTD)

Timeline

  • 2025-09-25: disclosed: Initial disclosure and CISA KEV addition
  • 2025-09-25: kev added
  • 2025-11-05: other: Cisco updated advisory to include details on a new DoS attack variant

Related threats