Remote Code Execution Vulnerability in Cisco Secure Firewall and IOS Software
CVE-2025-20363

9CRITICAL

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20363?

A vulnerability exists in the web services of multiple Cisco products, including the Secure Firewall ASA and FTD Software, as well as IOS, IOS XE, and IOS XR software. This flaw arises from inadequate validation of user-supplied input in HTTP requests, allowing both unauthenticated and authenticated attackers to potentially execute arbitrary code remotely. Successful exploitation could grant attackers root access, leading to full control over the affected devices. Attackers may need to gather additional system information and circumvent exploit mitigations to carry out the attack effectively. Organizations using the affected products should review their systems and implement necessary security measures.

Affected Version(s)

Cisco Adaptive Security Appliance (ASA) Software 9.8.1

Cisco Adaptive Security Appliance (ASA) Software 9.8.1.5

Cisco Adaptive Security Appliance (ASA) Software 9.8.1.7

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20363 : Remote Code Execution Vulnerability in Cisco Secure Firewall and IOS Software