PT-2025-39421 · Cisco · Cisco Secure Firewall Asa +2
Published
2025-09-25
·
Updated
2025-11-17
·
CVE-2025-20362
CVSS v3.1
8.6
8.6
High
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software versions prior to the fix included in the patch released in September 2025
Cisco IOS Software versions prior to the fix included in the patch released in September 2025
Cisco IOS XE Software versions prior to the fix included in the patch released in September 2025
Cisco IOS XR Software versions prior to the fix included in the patch released in September 2025
Description
A flaw exists in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. This issue allows an unauthenticated, remote attacker to bypass authorization controls and access restricted URL endpoints related to remote access VPN functionality. The vulnerability has been actively exploited in attacks, with reports indicating attempted exploitation and compromise of critical infrastructure. Approximately 34,000 devices are estimated to be vulnerable worldwide. The attacks have been linked to the ArcaneDoor threat actor, potentially a Chinese-backed group. Exploitation can lead to unauthorized access, potential espionage, and disruption of network services. The vulnerability is often chained with CVE-2025-20333. The exploitation of this vulnerability can force firewalls into reboot loops.
Recommendations
Update Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software to the latest version released in September 2025.
Update Cisco IOS Software to the latest version released in September 2025.
Update Cisco IOS XE Software to the latest version released in September 2025.
Update Cisco IOS XR Software to the latest version released in September 2025.
Fix
DoS
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-11751
CVE-2025-20362
Affected Products
Cisco Asa
Cisco Secure Firewall Asa
Cisco Secure Firewall Threat Defense
References · 209
- https://nvd.nist.gov/vuln/detail/CVE-2025-20362 · Security Note
- https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-11751 · Security Note
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW · Vendor Advisory
- https://twitter.com/johndjohnson/status/1973468491844882584 · Twitter Post
- https://t.me/aptreports/22379 · Telegram Post
- https://reddit.com/r/sysadmin/comments/1nqu8wa/cisco_asa_under_fire_urgent_zeroday_duo_actively · Reddit Post
- https://twitter.com/transilienceai/status/1974705523514658883 · Twitter Post
- https://twitter.com/Cloudforce_One/status/1972387788692795424 · Twitter Post
- https://twitter.com/dradisfw/status/1977819142586863674 · Twitter Post
- https://reddit.com/r/cybersecurity/comments/1ow73ik/cisco_asa_zerodays_under_active_exploitation_cisa · Reddit Post
- https://twitter.com/upgradeoptions/status/1988595886260097279 · Twitter Post
- https://t.me/NeKaspersky/4664 · Telegram Post
- https://twitter.com/PVynckier/status/1987528446671564836 · Twitter Post
- https://t.me/aptreports/22383 · Telegram Post