Skip to main content

CVE detail

CVE-2025-20333

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of the affected device.

CVSS 9.9 · CriticalBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
30 evidence mentions in the snapshot
Diversity score
20.0
12 sources across 5 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
1
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
30 source links · newest first
  • oitation of Cisco Catalyst SD-WAN vulnerabilities May 14, 2026 12:02 Cisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage. UAT-4356's Targeting of Cisco Firepower Devices April 23,

    vendorblog.talosintelligence.comJul 1, 2026, 10:00 AM
  • e following vulnerabilities before customers upgraded to the fixed releases that were made available in September 2025: CVE-2025-20333: Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability CVE-2025-20362: Cisco Secure Firewall Adaptive Security Applianc

    vendorsec.cloudapps.cisco.comMay 19, 2026, 5:49 PM
  • Security researchers have discovered a chilling backdoor aimed at Cisco System firewalls that exploits unpatched vulnerabilities to maintain persistence, even after patching. This means that attackers can continue to access compromised devices without re-exploiting the holes. At risk are devices running Cisco ASA or Firepower software, including certain Firepower and Secure Firewall devices. So far, however, […]

    newswww.csoonline.comApr 28, 2026, 1:31 AM
  • CISA said a federal Cisco Firepower ASA device was infected with the FIRESTARTER backdoor in Sept 2025, and it survived security patches. CISA revealed that a U.S. federal civilian agency’s Cisco Firepower device running ASA software was compromised in September 2025 by the FIRESTARTER backdoor. The malware reportedly persisted even after security patches were applied, […]

    newssecurityaffairs.comApr 25, 2026, 12:00 AM
  • The malware provides remote access and control of infected devices and maintains post-patching persistence.

    newswww.securityweek.comApr 24, 2026, 11:26 AM
  • Suspected state-sponsored attackers are using a custom backdoor to persistently compromise Cisco security devices (firewalls), the US CISA and the UK National Cyber Security Centre warned on Thursday. “The [Firestarter] malware (…) is relevant for both Cisco Firepower and Secure Firewall devices; however, CISA has only observed a successful implant of the malware in the wild on a Cisco Firepower device running ASA software,” the Cybersecurity and Infrastructure Security Agency noted. CISA also shared threat … More →

    newswww.helpnetsecurity.comApr 24, 2026, 9:56 AM
  • Cisco has handed security teams one of the largest ever patching workloads affecting its firewall products, including fixes for two ‘perfect 10’ vulnerabilities in the company’s Secure Firewall Management Center (FMC) Software. Overall, the March 4 release, the first of its semiannual firewall updates for 2026, addresses 25 security advisories covering 48 individual CVEs. The […]

    newswww.csoonline.comMar 5, 2026, 5:19 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Adopting a counterintelligence mindset in luxury logistics In this Help Net Security interview, Andrea Succi, Group CISO at Ferrari Group, discusses how cybersecurity is integrated into every aspect of the logistics industry. He explains why protecting data can be as critical as securing physical assets and how a layered defense approach helps safeguard both. Succi adds that awareness, collaboration, and … More →

    newswww.helpnetsecurity.comNov 16, 2025, 9:00 AM
  • Federal agencies have reported as ‘patched’ ASA or FTD devices running software versions vulnerable to attacks.

    newswww.securityweek.comNov 13, 2025, 3:05 PM
  • CISA has ordered US federal agencies to fully address two actively exploited vulnerabilities (CVE-2025-20333, CVE-2025-20362) in Cisco Adaptive Security Appliances (ASA) and Firepower firewalls. “In CISA’s analysis of agency-reported data, CISA has identified devices marked as ‘patched’ in the reporting template, but which were updated to a version of the software that is still vulnerable to the threat activity outlined in [Emergency Directive 25-03, released on September 25, 2025],” the agency stated on Wednesday. “CISA … More →

    newswww.helpnetsecurity.comNov 13, 2025, 2:08 PM
  • 10th November – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 10th November, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The US Congressional Budget Office (CBO) has confirmed a cyber attack that resulted in a suspected foreign threat actor breaching its network and potentially exposing sensitive communications between congressional offices and CBO […]

    vendorresearch.checkpoint.comNov 10, 2025, 1:39 PM
  • Cisco patched a critical flaw in its Unified Contact Center Express (UCCX) software that allowed attackers to execute commands with root privileges. Cisco released security updates to address a critical vulnerability, tracked as CVE-2025-20354 (CVSS score 9.8), in the Unified Contact Center Express (UCCX) software. An attacker can exploit the flaw to execute commands with root […]

    newssecurityaffairs.comNov 7, 2025, 11:37 AM
  • Cisco released patches for two critical vulnerabilities in its Unified Contact Center Express (CCX) that could allow attackers to bypass authentication and execute commands as root on the underlying system. The company also warned today about a new attack variation targeting two previously patched vulnerabilities in its Secure Firewall Adaptive Security Appliance (ASA) and Secure […]

    newswww.csoonline.comNov 7, 2025, 1:45 AM
  • Cisco warns of a new attack variant exploiting CVE-2025-20333 and CVE-2025-20362 in Secure Firewall ASA and FTD devices. Cisco warned of a new attack variant targeting vulnerable Secure Firewall ASA and FTD devices by exploiting the vulnerabilities CVE-2025-20333 and CVE-2025-20362. “On November 5, 2025, Cisco became aware of a new attack variant against devices running […]

    newssecurityaffairs.comNov 6, 2025, 6:26 PM
  • The flaws allow attackers to execute arbitrary code remotely and elevate their privileges to root on an affected system.

    newswww.securityweek.comNov 6, 2025, 10:20 AM
  • GreyNoise has discovered that attacks exploiting Cisco, Fortinet, and Palo Alto Networks vulnerabilities are launched from the same infrastructure.

    newswww.securityweek.comOct 10, 2025, 12:44 PM
  • Cisco ASA / FTD WebVPN Vulnerabilities

    exploithorizon3.aiOct 9, 2025, 9:19 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Keeping the internet afloat: How to protect the global cable network The resilience of the world’s submarine cable network is under new pressure from geopolitical tensions, supply chain risks, and slow repair processes. A new report from the Center for Cybersecurity Policy and Law outlines how governments and industry can work together to strengthen this critical infrastructure. Cyber risk quantification … More →

    newswww.helpnetsecurity.comOct 5, 2025, 8:00 AM
  • Despite Cisco and various cybersecurity agencies warning about attackers actively exploting zero-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Adaptive Security Appliances (ASA) for months, there are still around 48,000 vulnerable appliances out there. The number is provided by the Shadowserver Foundation, which is scanning for internet-facing vulnerable Cisco ASA/FTD instances every day. A majority of those are located in the US, and the rest mostly in the UK, Japan, Russia, Germany, and Canada. Surge in … More →

    newswww.helpnetsecurity.comOct 1, 2025, 10:10 AM
  • 29th September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 29th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Stellantis, Automotive maker giant which owns Citroën, FIAT, Jeep, Chrysler, and Peugeot, has suffered a data breach that resulted in exposure of North American customer contact information after attackers accessed a third-party […]

    vendorresearch.checkpoint.comSep 29, 2025, 12:43 PM
  • CVE-2025-20333, CVE-2025-20362 and CVE-2025-20363 affect multiple Cisco products, and are being exploited by a threat actor linked to the ArcaneDoor campaign.

    vendorunit42.paloaltonetworks.comSep 26, 2025, 8:30 PM
  • UK NCSC warns that threat actors exploited Cisco firewall zero-days to deploy new malware strains RayInitiator and LINE VIPER. The U.K. NCSC reported that threat actors exploited recently disclosed Cisco firewall flaws (CVE-2025-20362, CVE-2025-20333) in zero-day attacks to deploy novel malware families, RayInitiator and LINE VIPER. These malware mark a major evolution from earlier campaigns, […]

    newssecurityaffairs.comSep 26, 2025, 11:49 AM
  • A widespread campaign aimed at breaching organizations via zero-day vulnerabilities in Cisco Adaptive Security Appliances (ASA) has been revealed by the US, UK, Canadian and Australian cybersecurity agencies. The suspected state-sponsored threat actor behind it is believed to be the one that perpetrated the ArcaneDoor attack campaign in 2023 and 2024, when they used custom malware to disable logging and preventing the creation of a crash dump (“Line Dancer”) and to install a backdoor that … More →

    newswww.helpnetsecurity.comSep 26, 2025, 11:19 AM
  • Leading to remote code execution and privilege escalation, the flaws were exploited on Cisco ASA 5500-X series devices that lack secure boot.

    newswww.securityweek.comSep 26, 2025, 7:05 AM
  • A critical zero-day vulnerability in certain Cisco Systems firewalls has to be patched immediately, US and UK cyber authorities warned Thursday. They said exploits of the hole are part of ongoing attacks on these and other network perimeter devices. The UK’s National Cyber Security Centre (NCSC) called the alert from Cisco a “significant update” on […]

    newswww.csoonline.comSep 25, 2025, 9:15 PM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds CISCO Secure Firewall ASA and Secure FTD flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CISCO Secure Firewall ASA and Secure FTD flaws to its Known Exploited Vulnerabilities (KEV) catalog. CISA urges Federal Agencies to identify and mitigate potential compromise […]

    newssecurityaffairs.comSep 25, 2025, 7:45 PM
  • No excerpt available.

    Mitigationwww.cisa.govSep 25, 2025, 4:15 PM
  • No excerpt available.

    Vendor Advisorysec.cloudapps.cisco.comSep 25, 2025, 4:15 PM
  • No excerpt available.

    Vendor Advisorysec.cloudapps.cisco.comSep 25, 2025, 4:15 PM
  • 4 hours — representing the third-ever emergency directive since the agency’s founding. Both vulnerabilities, tracked as CVE-2025-20333 and CVE-2025-20362 , have been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. ‍ Resurgent Brute Force Attacks Against Cisco SSL VPNs After investigating activity against our Cisco profiles, GreyNoise ide

    vendorwww.greynoise.ioSep 4, 2025, 12:00 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence