CRITICAL

CVE-2025-20333

Cisco Adaptive Security Appliance Software 2025-09-25 CVSS v3.1
CVSS
9.9
KEV

Description

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device.

This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of the affected device.

Summary dbcve.org

Authenticated command injection in Cisco ASA/FTD VPN web server. Attacker with valid VPN credentials sends specially crafted HTTP(S) requests with improperly validated input, achieving arbitrary code execution as root and full device compromise.

Mitigation

Apply Cisco-supplied patches for ASA and FTD when available; restrict VPN user base to trusted personnel; monitor for unauthorized access attempts.

Weakness (CWE)

CWE-120 Classic Buffer Overflow

EPSS Score

70.65%
Probability of exploitation in next 30 days
99.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE