CVE-2025-20333 is a critical buffer overflow vulnerability in the VPN web server component of Cisco ASA and Firepower Threat Defense Software that allows authenticated remote attackers to execute arbitrary code as root. This vulnerability is actively being exploited in the wild and affects internet-facing VPN appliances that are commonly deployed with public internet access.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
📅 CVE Published: 2025-09-25
📅 Added to CISA KEV: 2025-09-25 0 DAY
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat ...
CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC. The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication. Description.Vulnerability Check: Determine if a target is vulnerable to CVE-2025-32433. Exploit Execution: Execute arbitrary commands.
CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their ...
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.