Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability
TL;DR 📌
A critical remote code execution vulnerability has been identified in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. This flaw allows authenticated attackers to execute arbitrary code on affected devices. Immediate software updates are recommended, as there are no workarounds available.
What happened 🕵️♂️
A vulnerability (CVE-2025-20333) has been discovered in the VPN web server of Cisco Secure Firewall ASA and FTD Software. This issue arises from improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN credentials could exploit this vulnerability by sending crafted HTTP requests, potentially leading to arbitrary code execution as root. This could result in a complete compromise of the affected device.
Affected products 🖥️
The vulnerability affects the following Cisco products running vulnerable releases:
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Secure Firewall Threat Defense (FTD) Software
Specific configurations that may be vulnerable include:
- AnyConnect IKEv2 Remote Access
- Mobile User Security (MUS)
- SSL VPN
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 1.0 | Initial public release. | |
| Cisco Secure Firewall ASA | Not specified | |
| Cisco Secure FMC | Not specified | |
| Cisco Secure FTD | Not specified |
Workarounds 🧯
There are no workarounds available to mitigate this vulnerability. Immediate software updates are the only recommended course of action.
Risk in context 🎯
With a CVSS score of 9.9, this vulnerability is classified as Critical. The exposure is significant as it requires only valid VPN credentials for exploitation, which could lead to complete device compromise. Organizations should prioritize patching affected systems to mitigate risk.
Fast facts ⚡
- Vulnerability ID: CVE-2025-20333
- Severity: Critical (CVSS 9.9)
- Attack Vector: Authenticated remote access
- Exploitation Potential: Arbitrary code execution
- Workarounds: None available
- Recommended Action: Upgrade to fixed software
For leadership 🧭
Executive summary. A near-maximum severity flaw in the VPN web server of Cisco ASA and FTD firewalls lets someone who already has valid VPN login details take full control of the device as root. There is no workaround, so patching is the only mitigation and should be treated as urgent.
Why it matters:
- The flaw sits in the VPN web server component used by AnyConnect IKEv2 Remote Access, Mobile User Security, and SSL VPN — services many organisations expose to remote staff.
- Exploitation requires only valid VPN credentials, not a network foothold, so any account compromise (phishing, credential reuse) could become a path to full firewall takeover.
- Successful exploitation gives arbitrary code execution as root, meaning complete compromise of the perimeter security appliance itself, not just a service running on it.
- With no workaround published, devices remain exposed until the software is actually upgraded.
Now / Next / Later:
- Now: Identify every ASA and FTD device running VPN web services (AnyConnect IKEv2, MUS, SSL VPN) and check its software train against Cisco’s fixed releases.
- Next: Schedule an emergency change window to upgrade affected ASA and FTD devices to the first fixed release for their train, prioritising internet-facing VPN gateways.
- Later: Build ASA/FTD patch tracking into routine change management and tighten VPN account hygiene (MFA, credential rotation) so a leaked password alone can’t become a root compromise.