Junglewise Threat Intelligence

CVE-2026-20008: Cisco Secure Firewall ASA and FTD Lua code injection in CLI commands

CVE-2026-20008 · Severity: medium · CVSS 6 · Published 2026-03-04

Technologies: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software. Vendors: Cisco.

Executive brief

Cisco Secure Firewall devices (ASA and FTD) contain a vulnerability in certain CLI commands that allows authenticated administrators to inject and execute arbitrary Lua code with root privileges. A malicious administrator could exploit this to gain complete control over the firewall's underlying operating system, compromising network security and enabling data theft or system takeover.

Technical details

This vulnerability is a Lua code injection flaw (CWE-78: Improper Neutralization of Special Elements) in CLI command handling. The root cause is insufficient input sanitization of user-supplied parameters in a small subset of CLI commands. An authenticated attacker with valid Administrator credentials can craft malicious Lua code as a CLI parameter to inject arbitrary code that executes as the root user on the appliance's underlying operating system. The attack vector is local; no network connectivity is required. Cisco has released software updates to fix this vulnerability, and no workarounds are available.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Multiple versions vulnerable; see Cisco Software Checker for affected releases
  • Cisco Secure Firewall Threat Defense (FTD) Software Multiple versions vulnerable; see Cisco Software Checker for affected releases

Timeline

  • 2026-03-04: disclosed: Cisco Security Advisory published
  • 2026-03-04: patched: Software updates available via Cisco Software Checker

References

Related threats