logo

Hackers Exploiting Cisco Firepower Devices’ Using n-day Vulnerabilities to Gain Unauthorized Access

ID: 00051ffe-ac5b-528c-85af-8cc45182d60f

STIX ID: report--00051ffe-ac5b-528c-85af-8cc45182d60f

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-04-25

Date Updated: 2026-04-25

Author: Abinaya

...
...

State-sponsored threat group UAT-4356 is actively exploiting two n-day Cisco FXOS vulnerabilities (CVE-2025-20333, CVE-2025-20362) to install the FIRESTARTER backdoor on ASA/FTD appliances; the implant injects shellcode into the LINA process, hooks a WebVPN XML handler to execute commands conditionally, uses a transient boot-mount persistence that is removable by hard reboot but ultimately requires reimaging, and detection/mitigation guidance includes applying vendor patches, reimaging affected devices, killing compromised processes, and deploying Snort rules 65340, 46897 and 62949.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.