Executive brief
Cisco Secure Firewall ASA, Threat Defense, and multiple IOS platforms include web service components (SSL VPN, management interfaces) used to manage and provide remote access to network devices. An unauthenticated attacker can send specially crafted HTTP requests to exploit improper input validation, achieving arbitrary code execution with root privileges and complete device compromise.
Technical details
This vulnerability exists in the HTTP request handling of web services across multiple Cisco platforms due to improper validation of user-supplied input (CWE-122). For ASA and FTD, the attack requires no authentication; for IOS, IOS XE, and IOS XR, the attacker must be authenticated with low privileges. The vulnerability is reachable over the network on any affected device with vulnerable configuration features enabled (SSL VPN, Remote Access VPN, or HTTP server). A successful exploit allows arbitrary code execution as root. Patches have been released by Cisco. The vulnerability has not been observed exploited in the wild as of the published date, though post-disclosure exploitation may occur.
Affected products
- Cisco Secure Firewall ASA Software Multiple versions with vulnerable configuration (see advisory for details)
- Cisco Secure Firewall Threat Defense Software Multiple versions with vulnerable configuration (see advisory for details)
- Cisco IOS Software Versions with Remote Access SSL VPN feature enabled
- Cisco IOS XE Software Versions with Remote Access SSL VPN feature enabled
- Cisco IOS XR Software 32-bit versions on Cisco ASR 9001 Routers with HTTP server enabled
Timeline
- 2025-09-25: disclosed: Cisco security advisory published
- 2025-11-06: other: Advisory last updated (Version 1.1)