Junglewise Threat Intelligence

CVE-2025-20363: Cisco multiple platforms code execution in web services

CVE-2025-20363 · Severity: critical · CVSS 9 · Published 2025-09-25

Technologies: Cisco Secure Firewall ASA Software, Cisco IOS XE Software, Cisco Ios Software, Cisco Secure Firewall Threat Defense Software, Cisco IOS XR Software. Vendors: Cisco.

Executive brief

Cisco Secure Firewall ASA, Threat Defense, and multiple IOS platforms include web service components (SSL VPN, management interfaces) used to manage and provide remote access to network devices. An unauthenticated attacker can send specially crafted HTTP requests to exploit improper input validation, achieving arbitrary code execution with root privileges and complete device compromise.

Technical details

This vulnerability exists in the HTTP request handling of web services across multiple Cisco platforms due to improper validation of user-supplied input (CWE-122). For ASA and FTD, the attack requires no authentication; for IOS, IOS XE, and IOS XR, the attacker must be authenticated with low privileges. The vulnerability is reachable over the network on any affected device with vulnerable configuration features enabled (SSL VPN, Remote Access VPN, or HTTP server). A successful exploit allows arbitrary code execution as root. Patches have been released by Cisco. The vulnerability has not been observed exploited in the wild as of the published date, though post-disclosure exploitation may occur.

Affected products

  • Cisco Secure Firewall ASA Software Multiple versions with vulnerable configuration (see advisory for details)
  • Cisco Secure Firewall Threat Defense Software Multiple versions with vulnerable configuration (see advisory for details)
  • Cisco IOS Software Versions with Remote Access SSL VPN feature enabled
  • Cisco IOS XE Software Versions with Remote Access SSL VPN feature enabled
  • Cisco IOS XR Software 32-bit versions on Cisco ASR 9001 Routers with HTTP server enabled

Timeline

  • 2025-09-25: disclosed: Cisco security advisory published
  • 2025-11-06: other: Advisory last updated (Version 1.1)

References

Related threats