PT-2025-39421 · Cisco · Cisco Secure Firewall Asa +2
Published
2025-09-25
·
Updated
2025-11-30
·
CVE-2025-20362
CVSS v3.1
8.6
8.6
High
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software versions (affected versions not specified)
Cisco IOS Software (affected versions not specified)
Cisco IOS XE Software (affected versions not specified)
Cisco IOS XR Software (affected versions not specified)
Description
A security issue exists in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. This flaw allows a remote, unauthenticated attacker to bypass authorization mechanisms and gain access to restricted URLs by sending specially crafted HTTP requests. The vulnerability is actively being exploited in attacks, with reports indicating attempted exploitation and potential compromise of critical infrastructure. Approximately 34,000 devices are estimated to be vulnerable worldwide. The attacks have been linked to the ArcaneDoor threat actor, potentially associated with China. Exploitation can lead to system compromise, the deployment of spyware, and the theft of sensitive data. The vulnerability is also chained with other vulnerabilities (CVE-2025-20333 and CVE-2025-20363) to achieve root access and establish firmware persistence. The attacks can force firewalls into reboot loops, disrupting network operations.
Recommendations
Update Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software to the latest version.
Update Cisco IOS Software to the latest version.
Update Cisco IOS XE Software to the latest version.
Update Cisco IOS XR Software to the latest version.
Monitor logs for anomalies.
Fix
DoS
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-11751
CVE-2025-20362
Affected Products
Cisco Asa
Cisco Secure Firewall Asa
Cisco Secure Firewall Threat Defense
References · 211
- https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-20362 · Security Note
- https://bdu.fstec.ru/vul/2025-11751 · Security Note
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW · Vendor Advisory
- https://reddit.com/r/cybersecurity/comments/1ow73ik/cisco_asa_zerodays_under_active_exploitation_cisa · Reddit Post
- https://t.me/purp_sec/1184 · Telegram Post
- https://reddit.com/r/DefenceProfessionals/comments/1org847/cisco_warns_of_new_cyberattacks_exploiting · Reddit Post
- https://twitter.com/not2cleverdotme/status/1989427776407978438 · Twitter Post
- https://twitter.com/SimoKohonen/status/1971467824490217621 · Twitter Post
- https://t.me/EchelonEyes/4152 · Telegram Post
- https://twitter.com/Trej0Jass/status/1971454277861441794 · Twitter Post
- https://twitter.com/cyber_sec_raj/status/1971775806130344330 · Twitter Post
- https://twitter.com/HorstKrieger/status/1972530942473322986 · Twitter Post
- https://twitter.com/zeeshankghouri/status/1973723544476377378 · Twitter Post
- https://t.me/avleonovcom/1591 · Telegram Post