Executive brief
Cisco Secure Firewall devices (ASA and FTD) contain a vulnerability in certain CLI commands that allows authenticated administrators to inject and execute arbitrary Lua code with root privileges. A malicious administrator could exploit this to gain complete control over the firewall's underlying operating system, compromising network security and enabling data theft or system takeover.
Technical details
This vulnerability is a Lua code injection flaw (CWE-78: Improper Neutralization of Special Elements) in CLI command handling. The root cause is insufficient input sanitization of user-supplied parameters in a small subset of CLI commands. An authenticated attacker with valid Administrator credentials can craft malicious Lua code as a CLI parameter to inject arbitrary code that executes as the root user on the appliance's underlying operating system. The attack vector is local; no network connectivity is required. Cisco has released software updates to fix this vulnerability, and no workarounds are available.
Affected products
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Multiple versions vulnerable; see Cisco Software Checker for affected releases
- Cisco Secure Firewall Threat Defense (FTD) Software Multiple versions vulnerable; see Cisco Software Checker for affected releases
Timeline
- 2026-03-04: disclosed: Cisco Security Advisory published
- 2026-03-04: patched: Software updates available via Cisco Software Checker