Hackers Exploiting Cisco Firepower Devices’ Using n-day Vulnerabilities to Gain Unauthorized Access
ID: 00051ffe-ac5b-528c-85af-8cc45182d60f
STIX ID: report--00051ffe-ac5b-528c-85af-8cc45182d60f
Feed Name: cybersecurityNews.com
State-sponsored threat group UAT-4356 is actively exploiting two n-day Cisco FXOS vulnerabilities (CVE-2025-20333, CVE-2025-20362) to install the FIRESTARTER backdoor on ASA/FTD appliances; the implant injects shellcode into the LINA process, hooks a WebVPN XML handler to execute commands conditionally, uses a transient boot-mount persistence that is removable by hard reboot but ultimately requires reimaging, and detection/mitigation guidance includes applying vendor patches, reimaging affected devices, killing compromised processes, and deploying Snort rules 65340, 46897 and 62949.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
