CVE-2025-20333Active Exploitation(cisco / adaptive_security_appliance_software)

CRITICALCVSS 9.9 · CRITICALCISA KEV

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch cisco adaptive_security_appliance_software systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of the affected device.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-09-26. The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Weakness type (CWE)
CWE-120

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • adaptive_security_appliance_software
  • secure_firewall_threat_defense

Threat summary

  • Active exploitation appears in 28 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 50 mentions across 16 observed days

What's happening

  • Active exploitation reported across 28 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 16 signals
  • Technical details provided in 17 signals
  • General: 10 classified signals
  • Peaked 13d ago at 9 mentions (2026-04-24); latest day: 1
  • 50 total mentions across 16 days

Affected systems

Vendors
Products
adaptive_security_appliance_softwaresecure_firewall_threat_defense

1 version affected across 2 products

Deep dive

Activity timeline50 mentions / 16d
02579Mentions · 2026-03-20: 1Mentions · 2026-04-23: 5Mentions · 2026-04-24: 9Mentions · 2026-04-25: 9Mentions · 2026-04-26: 4Mentions · 2026-04-27: 8Mentions · 2026-04-28: 2Mentions · 2026-04-29: 1Mentions · 2026-04-30: 4Mentions · 2026-05-04: 1Mentions · 2026-05-07: 1Mentions · 2026-05-08: 1Mentions · 2026-05-16: 1Mentions · 2026-06-16: 1Mentions · 2026-06-19: 1Mentions · 2026-07-10: 1PoC Mentioned / Linked · 2026-04-24: 1PoC Mentioned / Linked · 2026-05-16: 1Exploit Tool / Code · 2026-04-23: 2Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-04-23: 5Active Exploitation · 2026-04-24: 6Active Exploitation · 2026-04-25: 7Active Exploitation · 2026-04-26: 3Active Exploitation · 2026-04-27: 3Active Exploitation · 2026-04-28: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-07: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-24: 3Patch / Workaround · 2026-04-25: 4Patch / Workaround · 2026-04-26: 2Patch / Workaround · 2026-04-27: 4Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-04-23: 3Technical Details · 2026-04-24: 4Technical Details · 2026-04-25: 2Technical Details · 2026-04-27: 3Technical Details · 2026-04-30: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 1Technical Details · 2026-06-16: 1Technical Details · 2026-07-10: 103-2004-2304-2404-2504-2604-2704-2804-2904-3005-0405-0705-0805-1606-1606-1907-10
Signal classification6 categories
Active Exploitation
2652.0%
General
1020.0%
Patch
612.0%
Disclosure
48.0%
Exploit
36.0%
PoC
12.0%
Referenced assets27 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-201
Active Exploitation1
2026-04-235
Active Exploitation5
2026-04-249
Active Exploitation5Exploit1General1Patch2
2026-04-259
Active Exploitation7Disclosure1General1
2026-04-264
Active Exploitation3Patch1
2026-04-278
Active Exploitation2Disclosure1General3Patch2
2026-04-282
Active Exploitation1General1
2026-04-291
Disclosure1
2026-04-304
Active Exploitation1General3
2026-05-041
Patch1
2026-05-071
Active Exploitation1
2026-05-081
Exploit1
2026-05-161
PoC1
2026-06-161
Disclosure1
2026-06-191
General1
2026-07-101
Exploit1
Full discourse20 posts
  • CISA Cyber@CISACyber
    Active Exploitation

    Just Released: Malware Analysis Report: FIRESTARTER Backdoor on threat actors exploiting CVE-2025-20333 & CVE-2025-20362 vulnerabilities to gain persistent remote access & control over Cisco Firepower & Secure Firewall products. Learn more 👉 https://go.dhs.gov/5Zw https://t.co/R3wYVVZbJ9

    Post summary

    The tweet announces a malware analysis report showing threat actors actively exploiting CVE‑2025‑20333 and CVE‑2025‑20362 to gain persistent remote access to Cisco Firepower and Secure Firewall products.

    423460189.9K
    299.5K followersView on X
  • 国家サイバー統括室(注意・警戒情報)@cyber_forecast
    General

    【注意喚起】 2026年4月30日、JPCERTがCisco ASAおよびFTDにおける複数の脆弱性(CVE-2025-20333、CVE-2025-20362)に関する注意喚起の更新等を掲載しています。ご確認ください。 https://x.com/jpcert/status/2049654217800134701

    Post summary

    JPCERT issued a notification update about multiple vulnerabilities (CVE‑2025‑20333 and CVE‑2025‑20362) affecting Cisco ASA and FTD.

    037047114.0K
    101.2K followersView on X
  • OFFA@0xOFFA
    Disclosure

    اول رايتب + فيديو نعملو انا و @george_adel_1 ياريت يبقا مفيد رابط الرايتب:https://medium.com/@redteam503/from-medium-to-critical-chaining-cve-2025-20362-cve-2025-20333-in-cisco-asa-ftd-across-20-9f6857bd7880 رابط الفيديو:https://www.youtube.com/watch?v=pbbP6NA0DqE

    Post summary

    The tweet links to a Medium post and a YouTube video that discuss a chain of newly disclosed Cisco ASA FTD CVEs, providing technical identifiers but no exploit, patch, or active exploitation details.

    05043272.7K
    321 followersView on X
  • JPCERTコーディネーションセンター@jpcert
    Patch

    Cisco ASAおよびFTDの脆弱性(CVE-2025-20333、CVE-2025-20362)に関する注意喚起を更新。本脆弱性を悪用して機器内に潜伏・持続するマルウェアの情報が公表されています。修正を未適用の場合は速やかに適用を、適用済みでも侵害有無の確認や影響調査を検討ください。^KK https://www.jpcert.or.jp/at/2025/at250021.html

    Post summary

    Cisco ASA and FTD devices are affected by CVE‑2025‑20333 and CVE‑2025‑20362; malware exploiting these vulnerabilities is in circulation, so patch promptly and assess for compromise.

    0902586.6K
    33.9K followersView on X
  • JPCERTコーディネーションセンター@jpcert
    General

    JPCERT/CC WEEKLY REPORT 2026-04-30を公開。セキュリティ関連情報は15件。SKYSEA Client ViewおよびSKYMEC IT Managerの脆弱性情報や、「Cisco ASAおよびFTDにおける複数の脆弱性(CVE-2025-20333、CVE-2025-20362)に関する注意喚起」の更新などを掲載しています。^MH https://www.jpcert.or.jp/wr/2026/wr260430.html

    Post summary

    The JPCERT weekly report lists several CVEs, but offers no PoCs, exploit details, active exploitation evidence, patches, or technical specifics.

    09217518.9K
    33.9K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Cisco Talos uncovers the FIRESTARTER backdoor in Arcane Door's latest attack on Firepower devices. Patch CVE-2025-20333 now to stop state-sponsored espionage. #CiscoSecurity #ArcaneDoor #Firestarter #InfoSec #CyberSecurity #APT #Firepower #PatchNow https://securityonline.info/cisco-firepower-firestarter-backdoor-arcane-door-analysis/ https://t.co/W3gBSVQTem

    Post summary

    Cisco Talos identifies a Firestarter backdoor in FirePower devices tied to Arcane Door and urges immediate patching of CVE‑2025‑20333 to counter potential state‑sponsored espionage.

    1901021.2K
    12.5K followersView on X
  • 二本松哲也@t_nihonmatsu
    Patch

    FIRESTARTER BackdoorはFirewallそのものを永続的な侵入基盤に変える攻撃です。 ・ファームウェア更新では除去されない ・ログに残らない ・ハード電源断でしか除去不可 CVE-2025-20333(認可不備) CVE-2025-20362(バッファオーバーフロー) 対象機器の特定(最優先) ・Cisco ASA / Firepower / FTD ・インターネット公開機器 パッチだけでは不十分 ・侵害前提で評価 ・過去に露出していたかが重要 フォレンジック前提 ・core dump取得 ・メモリ解析 ・YARA適用 検知時の対応 ・即時IR起動 ・横展開調査(認証情報漏洩) ・物理電源断(条件付き) 恒久対策 ・管理プレーン分離 ・TACACS+(TLS化) ・特権ID監査強化 ・エッジ機器のゼロトラスト化

    Post summary

    The post identifies a Firestarter backdoor targeting Cisco firewalls, cites specific CVEs, and recommends mitigation measures beyond patching.

    0311131.7K
    15.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CISA and NCSC 🇬🇧 release detailed analysis of FIRESTARTER backdoor targeting Cisco Firepower/ASA devices. APT actors exploit CVE-2025-20333/CVE-2025-20362, deploy persistent malware that survives firmware updates and reboots. Technical details: • Linux ELF backdoor hooks into LINA processing engine, enables arbitrary shell code execution • Maintains persistence through automatic relaunching, requires full power cycle to remove • Deployed alongside LINE VIPER implant for unauthorized VPN session creation bypassing authentication • Active since September 2025, observed activity as recent as March 2026 despite patching efforts • Emergency Directive 25-03 mandates FCEB agencies collect core dumps for CISA analysis Attack methodology: • Initial access via exploitation of Cisco ASA/FTD zero-day vulnerabilities before patches available • LINE VIPER creates unauthorized VPN sessions using dormant valid accounts • FIRESTARTER deployed as persistence mechanism, survives firmware updates • Full device configuration exposed including admin credentials, certificates, private keys DFIR artifacts: • Suspicious network connections to compromised Firepower devices during monitoring • Core dumps contain malware samples for forensic analysis • VPN session logs showing unauthorized authentication bypasses • Configuration changes indicating credential/certificate compromise #DFIR_Radar

    Post summary

    CISA/NCSC confirm active exploitation of CVE‑2025‑20333/20362 via the FIRESTARTER backdoor on Cisco Firepower/ASA devices since September 2025, with detailed technical findings presented in the report.

    200421.6K
    1.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    FIRESTARTER backdoor on Cisco ASA/Firepower devices persists through patches and reboots by hooking the LINA firewall process. Only complete power disconnection for 1+ minutes removes it. Key findings from CISA/NCSC joint analysis: • Targets CVE-2025-20333/20362 (patched Sept 2025), but survives post-patch via boot script modification • Hooks LINA process memory, triggers via crafted WebVPN requests without new listeners • Persistence: writes to /opt/cisco/platform/logs/var/log/svc_samcore.log, modifies CSP_MOUNT_LIST boot script • UAT-4356/STORM-1849 actor used it to redeploy LINE VIPER implant in March 2026 on federal agency device • Anti-forensic techniques require Cisco TAC disk imaging vs. open-source acquisition Detection artifacts: - /usr/bin/lina_cs (active binary) - Modified CSP_MOUNT_LIST with appended persistence commands - Shellcode injection before libstdc++.so text segment Hunt with CISA YARA rules CISA_261290_01/02 against core dumps. Audit VPN sessions for former employee accounts used for credential bypass. #DFIR_Radar

    Post summary

    The briefing confirms active exploitation of CVE‑2025‑20333/20362 via a persistent backdoor on Cisco ASA/Firepower devices, detailing its hooking and boot‑script persistence tactics, detection artifacts, and that only a complete power cycle cleans the device.

    101501.5K
    1.7K followersView on X
  • Cyber Recon@KaliSushanth
    Active Exploitation

    🚨 Cisco Firepower devices are under active attack! UAT-4356 is exploiting CVE-2025-20333 & CVE-2025-20362 to deploy the FIRESTARTER backdoor. ✅ Hard reboot devices ✅ Reimage systems ✅ Apply Cisco patches ✅ Follow CISA Directive 25-03 Patch now! #CyberSecurity #Cisco

    Post summary

    The post warns that Cisco Firepower devices are currently being exploited by UAT-4356 using CVE-2025-20333 and CVE-2025-20362 to install a backdoor, urging immediate patching, rebooting, and following CISA directives.

    11020724
    2 followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    【Cisco ASAおよびFTDにおける複数の脆弱性(CVE-2025-20333、CVE-2025-20362)に関する注意喚起】 JPCERT/CCがCisco ASA/FTDの注意喚起を4月27日に更新しました。今回の要点は、CVE-2025-20333やCVE-2025-20362へのパッチ適用だけで終わらないことです。 Ciscoは、脆弱性修正後も残置し得る永続化機構やFIRESTARTERバックドアに関する情報を公開しており、JPCERT/CCも国内に影響を受けるホストが多数存在するとしています。境界機器はEDRが入りにくく、侵害されるとVPNや内部ネットワークへの入口として使われ続けるおそれがあります。 防御側は、ASA/FTDの対象バージョン、VPN Webサービス有効化状況、Cisco/Talos/CISAの検出手順、再イメージ化要否、証明書・鍵・ローカルパスワードのリセットを確認すべきです。連休前に「更新済みだから安全」と判断するのは危険です。 #サイバーセキュリティ #JPCERTCC #Cisco #ASA #FTD #CVE202520333 #CVE202520362 #FIRESTARTER https://www.jpcert.or.jp/at/2025/at250021.html

    Post summary

    JPCERT/CC warns that patching Cisco ASA/FTD CVE‑2025‑20333 and CVE‑2025‑20362 alone is insufficient because of persistent mechanisms and a FIRESTARTER backdoor; additional mitigations such as re‑imaging and credential resets are recommended.

    11001929
    3.5K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-32002 2 - CVE-2025-20333 3 - CVE-2026-20131 4 - CVE-2026-33626 5 - CVE-2024-57726 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post enumerates five trending CVE identifiers without offering any further detail or context.

    00021725
    1.7K followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 تحذير من البوابة الخلفية "FIRESTARTER" في جدران الحماية من Cisco ASA حذرت السلطات الأمريكية والبريطانية من وجود بوابة خلفية تسمى "FIRESTARTER" يستغلها المهاجمون في جدران الحماية من Cisco ASA. يعود سبب حدوث ذلك إلى ثغرات أمنية، منها CVE-2025-20362 و CVE-2025-20333. تأثرت أنظمة الشبكات والأجهزة المحمية. ولم يتم الإعلان عن إجراءات محددة للاستجابة، لكن يُنصح بـ تحديث البرامج وتفعيل الحماية اللازمة. 🔗 للمزيد: https://www.security.nl/posting/933973/VS+en+VK+waarschuwen+voor+%22FIRESTARTER%22+backdoor+in+Cisco+ASA-firewalls?channel=rss

    Post summary

    Security authorities warn of the Firestarter backdoor on Cisco ASA firewalls, citing CVE-2025-20362 and CVE-2025-20333. While no exploit code is shared, the text indicates attackers are actively using the vulnerability and recommends software updates as a mitigation.

    00030682
    268 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CISA reveals FIRESTARTER backdoor infected federal Cisco ASA device in Sept 2025, persisting through security patches. Malware survives firmware updates by hooking into LINA engine and maintaining persistence across reboots. Key technical details: • Exploits CVE-2025-20333 (missing authorization) and CVE-2025-20362 (buffer overflow) for initial compromise • Embeds in LINA network processing engine via XML handler hooks, enabling shellcode execution • Maintains persistence by intercepting termination signals and writing to reboot-persistent log locations • Used alongside LINE VIPER post-exploitation implant in coordinated APT campaign • Activates only after verifying victim-specific identifiers in WebVPN traffic Attack methodology: • Initial access through VPN credential exploitation or unauthenticated HTTP requests • Installs hooks in libstdc++ shared libraries and manipulates system files for persistence • Survives firmware updates unless full power cycle performed - patches don't remove existing infections • Self-reinstalls under new persistent paths while cleaning traces of previous installation DFIR artifacts: • YARA rules available from CISA for detecting malware in disk images and core dumps • Monitor for suspicious LINA process activity and unexpected XML handler modifications • Check reboot-persistent log locations for unauthorized binaries Complete device reimaging required for remediation. CISA Emergency Directive 25-03 mandates federal compliance. #DFIR_Radar

    Post summary

    CISA announces that the FIRESTARTER backdoor is actively exploiting CVE-2025-20333 and CVE-2025-20362 on federal Cisco ASA devices, persisting through firmware updates and necessitating full device reimaging for remediation.

    10011761
    1.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    State-sponsored UAT-4356 exploits n-day Cisco Firepower vulnerabilities to deploy FIRESTARTER backdoor. Campaign leverages transient persistence mechanism that survives graceful reboots but removed by hard power cycles. Key technical details: • Exploits CVE-2025-20333 and CVE-2025-20362 to compromise Cisco FXOS devices • FIRESTARTER injects into LINA process, replaces WebVPN XML handler with malicious Stage 2 shellcode • Persistence via CSP_MOUNT_LIST manipulation: copies to `/opt/cisco/platform/logs/var/log/svc_samcore.log` during reboot • Shellcode execution triggered by XML requests with custom magic byte prefixes (T1055.001, T1546.004) • Technical overlap with RayInitiator's Stage 3 capabilities confirms UAT-4356 attribution DFIR artifacts: • Process: `lina_cs` in kernel process list • Files: `/usr/bin/lina_cs`, `/opt/cisco/platform/logs/var/log/svc_samcore.log` • Memory: searches for byte sequence 0x1,0x2,0x3,0x4,0x5 in LINA process space Hunt with `show kernel process | include lina_cs` and verify file presence on affected Firepower devices. Hard reboot removes implant; reimaging recommended for complete remediation. Full IOCs in Cisco Security Advisory. #DFIR_Radar

    Post summary

    State-sponsored UAT-4356 actively exploits newly disclosed Cisco Firepower CVEs (CVE-2025-20333 & 20362) by injecting malicious code into the LINA process, establishing persistence, and enabling backdoor functionality, with detailed IOCs provided for detection.

    10110614
    1.3K followersView on X
  • Curtis Houghton@CurtisHoughton4
    PoC

    Cisco CVE-2025-20333 python script to check for vulnerable device #cisco #vulnerability #pentest #redteam #cybersecurity https://github.com/curtishoughton/Cisco-ASA-CVE-2025-20333-Scanner

    Post summary

    A GitHub Python script that scans Cisco devices for CVE‑2025‑20333 was shared, but no exploitation code, patch information, or active attack evidence is included.

    010101.6K
    169 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-7399 2 - CVE-2023-50224 3 - CVE-2025-48700 4 - CVE-2025-20333 5 - CVE-2026-5281 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet merely lists trending CVEs without providing technical details, evidence of exploitation, or mitigation information.

    00011811
    1.7K followersView on X
  • Cyber Recon@KaliSushanth
    Active Exploitation

    🚨 Cisco Firepower devices are under active attack! UAT-4356 is exploiting CVE-2025-20333 & CVE-2025-20362 to deploy the FIRESTARTER backdoor. ✅ Hard reboot devices ✅ Reimage systems ✅ Apply Cisco patches ✅ Follow CISA Directive 25-03 Patch now! #CyberSecurity #Cisco

    Post summary

    The post alerts that Cisco Firepower devices are presently being targeted using CVE-2025-20333 and CVE-2025-20362, and urges immediate patching and remediation.

    01010657
    2 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    ArcaneDoor threat actor develops new persistence mechanism for Cisco ASA/FTD that survives firmware upgrades to patched versions. CVE-2025-20333 (CVSS 9.9) actively exploited and on CISA KEV. #DFIR_Radar https://t.co/ZzJr80HYyt

    Post summary

    The tweet reports that ArcaneDoor has a persistence technique that survives firmware upgrades, and confirms CVE-2025-20333 is actively exploited and listed on CISA KEV.

    10010783
    1.3K followersView on X
  • NOCTIS@NoctisIntel
    Active Exploitation

    UAT-4356 (China-nexus) exploiting Cisco FXOS CVE-2025-20333: web mgmt RCE (unauth) CVE-2025-20362: CLI auth bypass Chain: bypass → RCE → firmware implant (REPTILE/SEASPY) Targets: enterprise/gov perimeter devices #ThreatIntel #APT #CVE #UAT4356

    Post summary

    China-nexus is actively exploiting Cisco FXOS via an unauthenticated web management RCE (CVE-2025-20333) and a CLI authentication bypass (CVE-2025-20362), subsequently implanting REPTILE/SEASPY firmware on enterprise and government perimeter devices.

    10010636
    3 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSciscoadaptive_security_appliance_software---
Appciscosecure_firewall_threat_defense---
Appciscosecure_firewall_threat_defense7.6.0--

Explore more