Geolocation Vulnerability in Cisco Secure Firewall Threat Defense Software
CVE-2025-20268
What is CVE-2025-20268?
A flaw in the Geolocation-Based Remote Access VPN feature of Cisco Secure Firewall Threat Defense Software presents a significant risk. Due to improper URL string parsing, an unauthenticated remote attacker may send specially crafted HTTP connections to the device, potentially bypassing critical geolocation policies. This vulnerability enables unauthorized access to restricted network areas, allowing connections that should otherwise have been denied based on the geographical location of the request.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Firepower Threat Defense Software 7.7.0
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved