{"id":7330,"date":"2025-10-01T10:03:35","date_gmt":"2025-10-01T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/01\/48-cisco-firewalls-vulnerable-to-actively-exploited-0-day-vulnerability-in-the-wild\/"},"modified":"2025-10-01T10:03:35","modified_gmt":"2025-10-01T10:03:35","slug":"48-cisco-firewalls-vulnerable-to-actively-exploited-0-day-vulnerability-in-the-wild","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/01\/48-cisco-firewalls-vulnerable-to-actively-exploited-0-day-vulnerability-in-the-wild\/","title":{"rendered":"48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild"},"content":{"rendered":"<p>    48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical zero-day vulnerability affecting thousands of Cisco firewalls is being actively exploited by threat actors in the wild.\u00a0<\/p>\n<p>The vulnerability, tracked as <a href=\"https:\/\/cybersecuritynews.com\/lessons-cisco-asa-0-day-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-20333<\/a>, poses an immediate risk to organizations worldwide with a CVSS score of 9.9, representing one of the most severe security flaws discovered in enterprise firewall infrastructure this year.<\/p>\n<p>According to data from The Shadowserver Foundation, over 48,800 unpatched IP addresses were identified on September 29, 2025, with the United States having received the most exposure.\u00a0<\/p>\n<p>The vulnerability affects <a href=\"https:\/\/cybersecuritynews.com\/cisa-warns-cisco-firewall-0-day-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cisco Secure Firewall Adaptive Security Appliance (ASA)<\/a> Software and Cisco Secure Firewall Threat Defense (FTD) Software, specifically targeting the VPN web server component that millions of organizations rely on for remote access capabilities.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"464\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-2-1024x464.png?resize=1024%2C464&#038;ssl=1\" alt=\"Cisco firewalls vulnerable\" class=\"wp-image-128550\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-2-1024x464.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-2-300x136.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-2-768x348.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-2-1536x696.png 1536w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-2-927x420.png 927w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-2-696x315.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-2-1068x484.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-2-1920x870.png 1920w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-2-150x68.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-2.png 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><\/figure>\n<\/div>\n<p class=\"has-text-align-center\">Cisco firewalls vulnerable<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-buffer-overflow-vulnerability-cve-2025-20333\"><strong>Buffer Overflow Vulnerability (CVE-2025-20333)<\/strong><\/h2>\n<p>The vulnerability stems from improper validation of user-supplied input in HTTP(S) requests processed by the VPN web server.\u00a0<\/p>\n<p>Classified as a CWE-120 buffer overflow, the flaw allows authenticated remote attackers to execute arbitrary code with root privileges on affected devices.\u00a0<\/p>\n<p>This level of access essentially grants complete control over the firewall, enabling attackers to modify security policies, intercept network traffic, and establish persistent backdoors.<\/p>\n<p>The attack vector requires valid VPN user credentials, which attackers can obtain through various methods including <a href=\"https:\/\/cybersecuritynews.com\/north-face-fashion-brand\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential stuffing<\/a>, <a href=\"https:\/\/cybersecuritynews.com\/evolving-phishing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing campaigns<\/a>, or exploiting weak authentication mechanisms.\u00a0<\/p>\n<p>Once authenticated, attackers can send specially crafted HTTP requests containing malicious payloads that overflow memory buffers, allowing shellcode execution in the context of the root user.<\/p>\n<p>Cisco\u2019s Product Security Incident Response Team (PSIRT) has confirmed active exploitation attempts and warns that successful attacks could result in complete device compromise.\u00a0<\/p>\n<p>The vulnerability affects devices running vulnerable releases of ASA or FTD software with specific configurations enabled, including AnyConnect IKEv2 Remote Access, Mobile User Security (MUS), and SSL VPN services.<\/p>\n<p>The affected configurations encompass critical enterprise features that organizations depend on for secure remote access. Vulnerable configurations include:<\/p>\n<ul class=\"wp-block-list\">\n<li>AnyConnect IKEv2 Remote Access with client services enabled<\/li>\n<li>Mobile User Security (MUS) implementations <\/li>\n<li>SSL VPN deployments <\/li>\n<\/ul>\n<p>These configurations are standard in enterprise environments, particularly those supporting remote workforce initiatives.\u00a0<\/p>\n<p>The vulnerability\u2019s severity is compounded by the fact that Cisco has confirmed no workarounds exist to mitigate the risk without applying security patches.<\/p>\n<p><strong>Missing Authorization Flaw (CVE-2025-20362)<\/strong><\/p>\n<p>A secondary vulnerability, CVE-2025-20362 (CVSS 6.5), accompanies the primary flaw and enables unauthenticated attackers to access restricted VPN endpoints that should require authentication.\u00a0<\/p>\n<p>This unauthorized access vulnerability, classified as CWE-862 (Missing Authorization), can serve as a reconnaissance tool for attackers planning more sophisticated attacks.<\/p>\n<figure class=\"wp-block-table aligncenter\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>CVE<\/strong><\/td>\n<td><strong>Title<\/strong><\/td>\n<td><strong>CVSS 3.1 Score<\/strong><\/td>\n<td><strong>Severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-20333<\/td>\n<td>VPN Web Server Remote Code Execution Vulnerability<\/td>\n<td>9.9<\/td>\n<td>Critical<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-20362<\/td>\n<td>VPN Web Server Unauthorized Access Vulnerability<\/td>\n<td>6.5<\/td>\n<td>Medium<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Cisco has released emergency security updates addressing both vulnerabilities and strongly recommends immediate patching.\u00a0<\/p>\n<p>Organizations should prioritize these updates given the active exploitation and the critical nature of affected systems.\u00a0<\/p>\n<p>The company also advises reviewing threat detection configurations for VPN services to enhance protection against authentication attacks and unauthorized connection attempts.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisco-firewalls-vulnerability-exploited\/\">48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisco-firewalls-vulnerability-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild A critical zero-day vulnerability affecting thousands of Cisco firewalls is being actively exploited by threat actors in the wild.\u00a0 The vulnerability, tracked as CVE-2025-20333, poses an immediate risk to organizations worldwide with a CVSS score of 9.9, representing one of the most severe [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-7330","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7330"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7330"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7330\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7330"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7330"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7330"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}