🔴 CVE-2025-20333

CVE-2025-20333 is a critical buffer overflow vulnerability in the VPN web server component of Cisco ASA and Firepower Threat Defense Software that allows authenticated remote attackers to execute arbitrary code as root. This vulnerability is actively being exploited in the wild and affects internet-facing VPN appliances that are commonly deployed with public internet access.

← Back to Overview
HIGH_RISK
Risk Level
T1190
MITRE Technique
9.9
CVSS Score
NETWORK
Attack Vector
VERY_HIGH
Deployment Risk

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

📅 CVE Published: 2025-09-25

📅 Added to CISA KEV: 2025-09-25 0 DAY

🎯 Recommendations:

🔍 Web Intelligence

Key Sources: