← Vulnerability feed

Vulnerability record · CVE-2025-20333 · published 25 September 2025

CVE-2025-20333: Cisco ASA and FTD VPN web server buffer overflow allows root RCE

Cisco · Adaptive Security Appliance Software

Cisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic buffer overflow (CWE-120). An attacker holding valid VPN user credentials can send crafted HTTP requests to execute arbitrary code as root, potentially fully compromising the device. Because these devices sit at the network edge and the flaw yields root code execution, it is a high-value target for defenders.

9.9 CVSS 3.1 Critical CISA KEV since 25 Sep 2025 EPSS 71% · top 0.6% CWE-120 · Classic buffer overflow
9.9CVSS 3.1 base score
71%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
11 Aug 2026Last modified by NVD

Description

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of the affected device.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw allows authenticated remote root code execution on edge firewalls, carries a CVSS score of 9.9, is listed in CISA KEV with a one-day remediation deadline and has a very high EPSS probability.

What it is

Cisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic buffer overflow (CWE-120). An attacker holding valid VPN user credentials can send crafted HTTP requests to execute arbitrary code as root, potentially fully compromising the device. Because these devices sit at the network edge and the flaw yields root code execution, it is a high-value target for defenders.

Impact

An authenticated remote attacker gains arbitrary code execution with root privileges on the firewall, allowing complete compromise of the device, including its configuration, VPN traffic handling and any trust relationships it holds.

Attack surface

Reachable over the network through the VPN web server via crafted HTTP(S) requests; the attacker must have valid VPN user credentials, and no user interaction is required. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:C) confirms network reachability, low attack complexity, low privileges and scope change.

Exploitation

CVE-2025-20333 was added to CISA KEV on 2025-09-25 with a due date of 2025-09-26, and EPSS gives a 30-day exploitation probability of 0.70651 (99.359th percentile), indicating active exploitation is expected or observed. No ransomware campaign use is documented in the record.

What to do

  • Apply the Cisco vendor advisory (cisco-sa-asaftd-webvpn-z5xP8EUB) patches for ASA and FTD immediately; this is the primary fix.
  • Follow CISA Emergency Directive 25-03 and the Cisco 'continued attacks' guidance, including any interim mitigations Cisco specifies for the VPN web server.
  • Restrict or disable remote VPN web server access where operationally possible, and limit exposure of management/VPN interfaces to trusted networks.
  • Audit and rotate VPN user credentials, enforce least privilege for VPN accounts, and monitor for credential abuse given the authenticated attack path.
  • If mitigations cannot be applied, follow BOD 22-01 guidance for cloud services or discontinue use of the affected product as directed.

Detection

  • Inspect ASA/FTD VPN web server logs and HTTP(S) request logs for malformed or unusually long requests targeting the web VPN endpoints.
  • Monitor for unexpected process crashes, restarts or reloads of ASA/FTD devices, which can accompany buffer overflow exploitation attempts.
  • Hunt for anomalous post-exploitation activity on the firewall, such as unexpected outbound connections, new local accounts or configuration changes.
  • Correlate VPN authentication events with subsequent suspicious HTTP requests from the same source to identify credentialed exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-20333 to the Known Exploited Vulnerabilities catalog on 25 September 2025 as "Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability". Required action: The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. Federal deadline 26 September 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-20333 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2025-20333), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.