logo

Rapid7 Details Cisco ASA Zero-Day Exploit Chain (CVE-2025-20362 & CVE-2025-20333)

ID: 9748dc8e-a441-5d72-8146-2364a5c9c4b3

STIX ID: report--9748dc8e-a441-5d72-8146-2364a5c9c4b3

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2025-10-07

Date Updated: 2026-04-22

Author: Ddos

...
...

Rapid7 disclosed a proof‑of‑concept exploit chain for two zero‑day flaws in Cisco Secure Firewall ASA/FTD WebVPN—CVE‑2025‑20362 (path traversal authentication bypass) and CVE‑2025‑20333 (Lua-based buffer overflow)—that together enable unauthenticated remote code execution; exploitation has been observed in targeted attacks, Cisco released patches (9.16.4.85+) and administrators are urged to patch or disable WebVPN.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.