Category
Vulnerability Management
Topic
Cisco Zero-Days CVE-2025-20352/-20333/-20362
Audience
Network and IT security officers
Reading time
approx. 6 minutes

On 25 September 2025, the manufacturer Cisco disclosed details of three critical security vulnerabilities. Two of the vulnerabilities in Cisco Adaptive Security Appliances (ASA) have raised alarm bells worldwide. The US Cybersecurity and Infrastructure Security Agency (CISA) has even issued an emergency directive (ED-25-03): all affected systems had to be patched by Friday evening at the latest.

What has happened?

The vulnerabilities CVE-2025-20333 and CVE-2025-20362 are already being actively exploited. Particularly dangerous: attackers can gain persistent access to networks, even after reboots or updates. Older ASA 5500-X devices, some of which are no longer supported, are particularly affected.

Cisco strongly recommends the immediate installation of the security updates, an assessment of all systems for compromise, and the change of all passwords, certificates and keys following the update. Businesses and public authorities should not waste any time: anyone still using unpatched Cisco devices risks not only data loss but also long-term network infiltration by highly professional attackers.

Scale of the issue worldwide and in Germany

According to measurements by Mint Secure, approx. 75,000 systems worldwide are affected and accessible from the internet. In Germany, approx. 700 systems are affected and accessible from the internet.

An overview of the three vulnerabilities

1

CVE-2025-20333: VPN Web Server Remote Code Execution (ASA/FTD)

A security vulnerability in the VPN web server of the Cisco Secure Firewall ASA software and the Cisco Secure Firewall Threat Defense (FTD) software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This is caused by insufficient validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN credentials can exploit the vulnerability using specially crafted HTTP requests, thereby executing arbitrary code with root privileges, which could lead to the device being completely compromised. Cisco has released software updates; there are no workarounds. Security advisory: cisco-sa-asaftd-webvpn-z5xP8EUB.

2

CVE-2025-20352: SNMP Denial of Service and Remote Code Execution (IOS/IOS XE)

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software, caused by a stack overflow condition, affects all SNMP versions. An authenticated, remote attacker with low privileges can trigger a denial-of-service condition via an SNMPv2c or older read-only community string, or via valid SNMPv3 credentials. An attacker with high privileges and administrative or Privilege 15 permissions can execute arbitrary code as the root user on devices running Cisco IOS XE Software. The vulnerability is exploited via a specially crafted SNMP packet over IPv4 or IPv6. Cisco has released updates; whilst there is no complete workaround, a mitigation is available. Security advisory: cisco-sa-snmp-x4LPhte.

3

CVE-2025-20362: VPN Web Server Unauthorised Access (ASA/FTD)

A security vulnerability in the VPN web server of the Cisco Secure Firewall ASA software and the Cisco Secure Firewall Threat Defense (FTD) software could allow an unauthenticated, remote attacker to access restricted URL endpoints that should normally require authentication. The cause is, once again, insufficient validation of user-supplied input in HTTP(S) requests. Cisco has released software updates; there are no workarounds. Security advisory: cisco-sa-asaftd-webvpn-YROOTUW.

Recommended immediate actions

  • Apply patches immediately: Update all affected ASA, FTD, IOS and IOS-XE systems to the patched versions without delay.

  • Check for compromise: Conduct an investigation on all systems for signs of compromise, even after patching.

  • Renew credentials: Systematically replace passwords, certificates and keys after the update.

  • Identify end-of-support devices: Prioritise replacing or isolating older ASA 5500-X devices that are no longer supported by the manufacturer.

“A Zero-Day vulnerability that is already being actively exploited and grants attackers access even after a reboot or update requires immediate action, not the next maintenance release.”
Mint Secure GmbH

How Mint Secure supports you

Defenders should act promptly and implement countermeasures. These are Zero-Day exploits being exploited by professional attackers.

🧯

Incident Response

We provide support in the event of suspected compromise of your Cisco systems with rapid analysis and containment.

🩹

Vulnerability Management

We help to identify affected systems and prioritise the implementation of patches.

🔎

forensics

We investigate whether and how your systems have already been compromised, and document the findings in a manner that stands up in court.

Conclusion

With CVE-2025-20352, CVE-2025-20333 and CVE-2025-20362, Cisco has disclosed three critical vulnerabilities, two of which are already being actively exploited as Zero-Day vulnerabilities and affect around 75,000 systems worldwide and around 700 in Germany.

Anyone operating affected Cisco ASA, FTD, IOS or IOS-XE systems should patch them immediately, check for compromise and reset all credentials before attackers gain permanent access.

Mint Secure provides consulting in the areas of incident response and forensics to prevent further damage and investigate attacks. Talk to us.