Rapid7 Details Cisco ASA Zero-Day Exploit Chain (CVE-2025-20362 & CVE-2025-20333)
ID: 9748dc8e-a441-5d72-8146-2364a5c9c4b3
STIX ID: report--9748dc8e-a441-5d72-8146-2364a5c9c4b3
Feed Name: securityonline.info
Threat Score
Rapid7 disclosed a proof‑of‑concept exploit chain for two zero‑day flaws in Cisco Secure Firewall ASA/FTD WebVPN—CVE‑2025‑20362 (path traversal authentication bypass) and CVE‑2025‑20333 (Lua-based buffer overflow)—that together enable unauthenticated remote code execution; exploitation has been observed in targeted attacks, Cisco released patches (9.16.4.85+) and administrators are urged to patch or disable WebVPN.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
