CVE-2025-20333 is a critical vulnerability affecting Cisco Secure Firewall ASA and FTD Software, allowing authenticated, remote attackers to execute arbitrary code on the VPN web server. With a CVSS score of 9.9, this flaw enables a low-privileged attacker to achieve root-level code execution and complete device compromise through crafted HTTP requests. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog and significant community discussion and media coverage, despite no public exploit code being readily available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.12, < 9.12.4.72CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.14, < 9.14.4.28CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.16, < 9.16.4.85CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.17.0, < 9.17.1.45CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.18, < 9.18.4.47CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.