Remote Code Execution Vulnerability in Cisco Secure Firewall and IOS Software
CVE-2025-20363
What is CVE-2025-20363?
A vulnerability exists in the web services of multiple Cisco products, including the Secure Firewall ASA and FTD Software, as well as IOS, IOS XE, and IOS XR software. This flaw arises from inadequate validation of user-supplied input in HTTP requests, allowing both unauthenticated and authenticated attackers to potentially execute arbitrary code remotely. Successful exploitation could grant attackers root access, leading to full control over the affected devices. Attackers may need to gather additional system information and circumvent exploit mitigations to carry out the attack effectively. Organizations using the affected products should review their systems and implement necessary security measures.
Affected Version(s)
Cisco Adaptive Security Appliance (ASA) Software 9.8.1
Cisco Adaptive Security Appliance (ASA) Software 9.8.1.5
Cisco Adaptive Security Appliance (ASA) Software 9.8.1.7