CVE-2025-20333 affects Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software with VPN web server (WebVPN) services enabled. The vulnerability resides in the VPN web services component and is due to inadequate validation of user-supplied input. Exploitation requires valid VPN credentials, but once exploited, it allows an attacker to achieve remote code execution with root privileges on the target device.
This flaw has been actively exploited in coordinated threat campaigns (linked to UAT4356 / Storm-1849) against perimeter Cisco devices. CISA has included CVE-2025-20333 in its Known Exploited Vulnerabilities (KEV) Catalog as part of Emergency Directive ED 25-03, requiring U.S. federal agencies to identify, mitigate, and remediate vulnerable systems.
| Product | Cisco ASA |
| Date | 2025-09-29 15:02:10 |
| Information |
|
Technical Summary
This is a Buffer Overflow vulnerability (CWE-120) with a CVSS v3.1 base score of 9.9 (Critical). The flaw stems from insufficient boundary checking in the VPN web services code path.
- Attack Requirements: Exploitation requires an attacker to reach the vulnerable WebVPN component and invoke the vulnerable input path. Valid VPN credentials are generally required for direct exploitation.
- Impact: Successful exploitation allows for arbitrary code execution with root privileges, enabling full device compromise (persistence, credential theft, log alteration, lateral movement).
- Observed Behavior: CVE-2025-20333 has been actively exploited in real-world environments. It has also been observed chained with CVE-2025-20362 (a missing authorization vulnerability), allowing attackers to move from unauthenticated access to RCE in some campaigns.
This vulnerability represents a severe risk to Internet-exposed ASA/FTD devices with WebVPN enabled.
Recommendations
- Immediate Patching: Update to Cisco ASA/FTD software versions that resolve CVE-2025-20333 without delay. Cisco has released patches for all supported product lines.
- Restrict VPN Web Services: Disable or restrict VPN web server / WebVPN services from untrusted networks until patches are applied.
- Forensic Analysis and Threat Hunting: Follow the forensic guidelines published by Cisco and CISA. Collect crash dumps, inspect for malware implants, and check for anomalous logs or unusual persistence mechanisms.
- Credential and Certificate Rotation: If exploitation is suspected, factory reset the device after patching, change all user VPN credentials, and reissue certificates and keys.
- Network Hardening: Limit exposure of management interfaces, apply segmentation controls, and ensure that only trusted IPs can access administrative endpoints.
- Incident Response Preparation: Be prepared for possible firmware-level compromise. In case of confirmed compromise, disconnect the device from the network, preserve evidence, and follow incident response protocols.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
