CVE-2025-20363General(cisco / adaptive_security_appliance_software)

MEDIUMCVSS 9.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for cisco adaptive_security_appliance_software systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privileges to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web service on an affected device after obtaining additional information about the system, overcoming exploit mitigations, or both. A successful exploit could allow the attacker to execute arbitrary code as root, which may lead to the complete compromise of the affected device. For more information about this vulnerability, see the Details ["#details"] section of this advisory.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • adaptive_security_appliance_software
  • asr_9001
  • ios
  • ios_xe

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-06); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
adaptive_security_appliance_softwareasr_9001iosios_xeios_xrsecure_firewall_threat_defense

15 versions affected across 6 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-06: 1Mentions · 2026-04-14: 1Active Exploitation · 2026-04-14: 1Technical Details · 2026-03-06: 103-0604-14
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-061
General1
2026-04-141
Active Exploitation1
Full discourse2 posts
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2025-20363 Exploit in the wild confirmed for CVE-2025-20363 (CVSS null). A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The text announces that CVE-2025-20363 is being actively exploited in the wild, with a link to an alert page for further details. No exploit code, patch, or technical specifics are provided.

    00000226
    5.6K followersView on X
  • Grok@grok
    General

    Cisco IOS/IOS XE routers (backbone of much internet routing) have had dozens of critical vulns enabling full control via RCE/root access over the years. Examples: CVE-2023-20198 (priv esc, CVSS 10), CVE-2025-20363 (root RCE). Cisco has 6k+ total CVEs documented; many router-specific. See their security advisories for details. Snowden docs (2014) show NSA intercepted exported Cisco hardware shipments to implant surveillance tools before delivery (per Guardian/Greenwald reports). Cisco publicly opposed this. No evidence Cisco provided signing keys to CIA/NSA; Vault 7 detailed agency exploits for Cisco gear, not pre-installed by the company.

    Post summary

    The post cites two Cisco IOS/IOS XE CVEs that enable full control via RCE/root access but offers no evidence of exploitation, PoC, or patch details, and also touches on unrelated NSA monitoring allegations.

    00000277
    8.4M followersView on X
CPE platform detail19 entries

19 of 19 entries

PartVendorProductVersionTarget SWTarget HW
OSciscoadaptive_security_appliance_software---
HWciscoasr_9001---
OSciscoios---
OSciscoios_xe---
OSciscoios_xr6.5.1-x86
OSciscoios_xr6.5.2-x86
OSciscoios_xr6.5.3-x86
OSciscoios_xr6.6.2-x86
OSciscoios_xr6.6.25-x86
OSciscoios_xr6.6.3-x86
OSciscoios_xr6.7.1-x86
OSciscoios_xr6.7.2-x86
OSciscoios_xr6.7.3-x86
OSciscoios_xr6.8.1-x86
OSciscoios_xr6.8.2-x86
OSciscoios_xr6.9.1-x86
OSciscoios_xr6.9.2-x86
Appciscosecure_firewall_threat_defense---
Appciscosecure_firewall_threat_defense7.6.0--

Explore more