Executive Summary
In September 2025, Cisco revealed that two zero-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) affecting ASA Firewall and FTD software were exploited in active campaigns. One flaw allowed authenticated remote code execution, while the other exposed restricted URL endpoints without authentication. Attackers leveraged these security gaps to potentially gain unauthorized access and control over vulnerable network infrastructure. Security advisories emphasized the need for immediate patching, with involvement from global cybersecurity agencies such as ACSC, CCCS, NCSC, and CISA in threat investigation and response.
This breach highlights a surge in zero-day exploitations against critical network appliances and underscores the evolving sophistication of attacker reconnaissance and exploitation cycles. The incident reflects an ongoing trend of targeting edge devices as organizations increase reliance on remote and hybrid work models.
Why This Matters Now
With thousands of organizations relying on Cisco firewall solutions as perimeter defenses, the exploitation of unpatched zero-day vulnerabilities enables attackers to bypass security controls, jeopardize business continuity, and facilitate lateral movement. Immediate remediation is critical as threat actors continue to ramp up automated scanning and exploitation of exposed infrastructure.
Attack Path Analysis
The adversary exploited internet-exposed Cisco ASA firewall zero-day vulnerabilities to gain initial access. Leveraging code execution or unauthorized endpoint access, they escalated privileges to control network devices. Lateral movement was enabled across impacted segments, potentially targeting additional devices and workloads. The attacker established command and control by manipulating outbound connections on compromised systems. Sensitive data and device configurations could then be exfiltrated via covert egress channels. Ultimately, the attacker could disrupt network availability or deploy further malicious actions, impacting business operations.
Kill Chain Progression
Initial Compromise
Description
Attacker exploited ASA firewall zero-days (CVE-2025-20333 & CVE-2025-20362) remotely to gain initial access to network devices exposed to the internet.
Related CVEs
CVE-2025-20333
CVSS 9.9A vulnerability in the VPN web server of Cisco Secure Firewall ASA and FTD Software allows authenticated, remote attackers to execute arbitrary code as root.
Affected Products:
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software – Affected versions prior to fixed releases
Cisco Secure Firewall Threat Defense (FTD) Software – Affected versions prior to fixed releases
Exploit Status:
exploited in the wildCVE-2025-20362
CVSS 7.5A vulnerability in the VPN web server of Cisco Secure Firewall ASA and FTD Software allows unauthenticated, remote attackers to access restricted URL endpoints.
Affected Products:
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software – Affected versions prior to fixed releases
Cisco Secure Firewall Threat Defense (FTD) Software – Affected versions prior to fixed releases
Exploit Status:
exploited in the wildCVE-2025-20363
CVSS 9A vulnerability in the web services of Cisco Secure Firewall ASA, FTD, IOS, IOS XE, and IOS XR Software allows unauthenticated, remote attackers to execute arbitrary code.
Affected Products:
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software – Affected versions prior to fixed releases
Cisco Secure Firewall Threat Defense (FTD) Software – Affected versions prior to fixed releases
Cisco IOS Software – Affected versions prior to fixed releases
Cisco IOS XE Software – Affected versions prior to fixed releases
Cisco IOS XR Software – Affected versions prior to fixed releases
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
External Remote Services
Valid Accounts
Phishing
Command and Scripting Interpreter
Network Service Scanning
Exploitation of Remote Services
Application Layer Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of System Components
Control ID: 6.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Art. 9
CISA ZTMM 2.0 – Inventory and Control of Assets
Control ID: Asset Management: AS-1
NIS2 Directive – Risk Management Measures
Control ID: Article 21(2) (b)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Cisco ASA firewall zero-days enable code execution and authentication bypass, threatening banking infrastructure with lateral movement and data exfiltration risks.
Health Care / Life Sciences
Zero-day exploitation of ASA firewalls compromises patient data protection through unauthorized access and potential HIPAA compliance violations requiring immediate patching.
Government Administration
Critical infrastructure vulnerabilities in Cisco firewalls expose government networks to remote code execution and unauthorized endpoint access by nation-state actors.
Telecommunications
ASA firewall zero-days threaten network infrastructure integrity through authentication bypass and code execution, requiring emergency security updates across service providers.
Sources
- Cisco warns of ASA firewall zero-days exploited in attackshttps://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-firewall-zero-days-exploited-in-attacks/Verified
- Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerabilityhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUBVerified
- Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerabilityhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUWVerified
- Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software, and IOS XR Software Web Services Remote Code Execution Vulnerabilityhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-code-exec-WmfP3h3OVerified
- CISA Issues Emergency Directive Requiring Federal Agencies to Identify and Mitigate Cisco Zero-Day Vulnerabilitieshttps://www.cisa.gov/news-events/news/cisa-issues-emergency-directive-requiring-federal-agencies-identify-and-mitigate-cisco-zero-dayVerified
- CISA Directs Federal Agencies to Identify and Mitigate Potential Compromise of Cisco Deviceshttps://www.cisa.gov/news-events/alerts/2025/09/25/cisa-directs-federal-agencies-identify-and-mitigate-potential-compromise-cisco-devicesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Distributed Zero Trust controls like segmentation, egress filtering, and inline threat detection would have limited attacker movement, prevented unauthorized outbound actions, and enabled rapid detection of anomalous traffic, reducing the attack’s progression across multiple kill chain stages.
Control: Cloud Firewall (ACF)
Mitigation: Restricts and monitors inbound access to trusted ports, limiting vulnerable endpoint exposure.
Control: Zero Trust Segmentation
Mitigation: Prevents lateral privilege abuse by isolating management, workloads, and admin services by policy.
Control: East-West Traffic Security
Mitigation: Blocks unauthorized workload-to-workload and cross-segment access from compromised devices.
Control: Egress Security & Policy Enforcement
Mitigation: Detects and blocks unauthorized outbound connections to attacker infrastructure.
Control: Encrypted Traffic (HPE) + Egress Security & Policy Enforcement
Mitigation: Detects and prevents unapproved data exfiltration events.
Enables rapid containment and response to disruptive or destructive actions.
Impact at a Glance
Affected Business Functions
- Network Security Operations
- Remote Access Services
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive network configurations and user credentials due to unauthorized access and code execution vulnerabilities.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce least-privilege network segmentation and microsegmentation for firewalls, admin services, and critical workloads.
- • Deploy cloud-native firewall controls and restrict inbound management access to minimize public exposure.
- • Implement robust egress filtering and real-time monitoring to detect and block suspicious outbound connections.
- • Continuously baseline, monitor, and respond to anomalies in both north-south and east-west traffic flows.
- • Regularly review and update security controls in line with zero trust principles and threat intelligence on device vulnerabilities.



