{"id":7218,"date":"2025-09-26T10:03:33","date_gmt":"2025-09-26T10:03:33","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/26\/cisco-asa-0-day-rce-vulnerability-actively-exploited-in-the-wild\/"},"modified":"2025-09-26T10:03:33","modified_gmt":"2025-09-26T10:03:33","slug":"cisco-asa-0-day-rce-vulnerability-actively-exploited-in-the-wild","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/26\/cisco-asa-0-day-rce-vulnerability-actively-exploited-in-the-wild\/","title":{"rendered":"Cisco ASA 0-Day RCE Vulnerability Actively Exploited in the Wild"},"content":{"rendered":"<p>    Cisco ASA 0-Day RCE Vulnerability Actively Exploited in the Wild<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cisco has issued an emergency security advisory warning of <a href=\"https:\/\/cybersecuritynews.com\/microsoft-sharepoint-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">active exploitation<\/a> of a critical <a href=\"https:\/\/cybersecuritynews.com\/helldown-ransomware-exploiting-zyxel-devices\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-day vulnerability<\/a> in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software platforms.\u00a0<\/p>\n<p>The vulnerability, tracked as CVE-2025-20333, carries a maximum CVSS score of 9.9 and enables authenticated remote attackers to execute arbitrary code with root privileges on affected devices.<\/p>\n<p>The vulnerability resides in the VPN web server component of both ASA and FTD software, specifically affecting devices with remote access VPN configurations enabled.<\/p>\n<p>\u00a0Cisco\u2019s Product Security Incident Response Team (PSIRT) confirmed active exploitation attempts and emphasized the critical nature of this security flaw, which could result in complete device compromise.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-cisco-asa-0-day-rce-vulnerability\"><strong>Cisco ASA 0-Day RCE Vulnerability<\/strong><\/h2>\n<p>The root cause of CVE-2025-20333 lies in improper validation of user-supplied input within HTTP(S) requests processed by the VPN web server.\u00a0<\/p>\n<p>This <a href=\"https:\/\/cybersecuritynews.com\/windows-heap-based-buffer-overflow-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">buffer overflow vulnerability<\/a> (CWE-120) allows authenticated attackers with valid VPN credentials to craft malicious HTTP requests that trigger code execution with elevated privileges.<\/p>\n<p>Vulnerable configurations include devices running ASA or FTD software with specific VPN features enabled, including AnyConnect IKEv2 Remote Access with client services (crypto ikev2 enable &lt;interface_name&gt; client-services port &lt;port_number&gt;), SSL VPN services (webvpn enable &lt;interface_name&gt;), and Mobile User Security (MUS) implementations.\u00a0<\/p>\n<p>The vulnerability specifically targets SSL listen sockets enabled by these configurations.<\/p>\n<p>The exploitation process requires attackers to first obtain valid VPN user credentials, after which they can send specially crafted HTTP requests to the targeted device\u2019s VPN web server.\u00a0<\/p>\n<p>Successful exploitation grants root-level access, potentially allowing threat actors to install persistent backdoors, exfiltrate sensitive network traffic, or pivot to internal network segments.<\/p>\n<p>The discovery and investigation of this vulnerability involved unprecedented collaboration between multiple international cybersecurity agencies, including the Australian Signals Directorate, the Australian Cyber Security Centre, the Canadian Centre for Cyber Security, the UK National Cyber Security Centre (NCSC), and the U.S. Cybersecurity &amp; Infrastructure Security Agency (CISA).<\/p>\n<p>This coordinated response suggests sophisticated threat actor involvement, likely nation-state or advanced persistent threat (APT) groups targeting critical infrastructure.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-unauthorized-access-vulnerability-cve-2025-20362\"><strong>Unauthorized Access Vulnerability (CVE-2025-20362)<\/strong><\/h2>\n<p>CVE-2025-20362 is an unauthenticated unauthorized access vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software.\u00a0<\/p>\n<p>Rated Medium severity with a CVSS 3.1 base score of 6.5, this flaw allows remote attackers to bypass authentication and access restricted URL endpoints.<\/p>\n<p>The vulnerability stems from improper validation of user-supplied input in HTTP(S) requests handled by the VPN web server. Specifically, certain URL endpoints that should require authentication fail to enforce access checks.\u00a0<\/p>\n<p>An attacker crafts a malicious HTTP request targeting these endpoints and can retrieve or interact with sensitive resources without any valid VPN credentials.<\/p>\n<figure class=\"wp-block-table aligncenter\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>CVE<\/strong><\/td>\n<td><strong>Title<\/strong><\/td>\n<td><strong>CVSS 3.1 Score<\/strong><\/td>\n<td><strong>Severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-webvpn-z5xP8EUB\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2025-20333<\/a><\/td>\n<td>Cisco Secure Firewall ASA\/FTD VPN Web Server Remote Code Execution Vulnerability<\/td>\n<td>9.9<\/td>\n<td>Critical<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-webvpn-YROOTUW\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2025-20362<\/a><\/td>\n<td>Cisco Secure Firewall ASA\/FTD VPN Web Server Unauthorized Access Vulnerability<\/td>\n<td>6.5<\/td>\n<td>Medium<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-mitigations\"><strong>Mitigations\u00a0<\/strong><\/h2>\n<p>Cisco emphasizes that no workarounds exist for vulnerabilities, making immediate software updates the only viable remediation strategy.\u00a0<\/p>\n<p>Organizations should prioritize patching all affected ASA and FTD devices using Cisco\u2019s Software Checker tool to identify vulnerable releases and appropriate fixed versions.<\/p>\n<p>The advisory specifically recommends reviewing threat detection configurations for VPN services using the command show running-config to identify vulnerable configurations. Network administrators should implement enhanced monitoring for unusual VPN authentication patterns and HTTP request anomalies targeting <a href=\"https:\/\/cybersecuritynews.com\/fortios-ssl-vpn-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">SSL VPN<\/a> endpoints.<\/p>\n<p>Given the active exploitation status and maximum severity rating, security teams should treat this vulnerability as a critical incident requiring emergency patching procedures.\u00a0<\/p>\n<p>Organizations unable to immediately patch should consider temporarily disabling vulnerable VPN configurations if operationally feasible, though Cisco notes this approach may impact business continuity for remote access requirements.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisco-asa-0-day-rce-vulnerability\/\">Cisco ASA 0-Day RCE Vulnerability Actively Exploited in the Wild<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisco-asa-0-day-rce-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco ASA 0-Day RCE Vulnerability Actively Exploited in the Wild Cisco has issued an emergency security advisory warning of active exploitation of a critical zero-day vulnerability in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software platforms.\u00a0 The vulnerability, tracked as CVE-2025-20333, carries a maximum CVSS score of 9.9 and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131],"tags":[130],"class_list":["post-7218","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7218"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7218"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7218\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}