🔴 CVE-2025-20362

CVE-2025-20362 is a missing authorization vulnerability in Cisco ASA and FTD VPN web servers that allows unauthenticated remote attackers to access restricted URL endpoints. The vulnerability is being actively exploited in the wild and affects internet-facing firewall appliances.

← Back to Overview
HIGH_RISK
Risk Level
T1190
MITRE Technique
6.5
CVSS Score
NETWORK
Attack Vector
VERY_HIGH
Deployment Risk

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

📅 CVE Published: 2025-09-25

📅 Added to CISA KEV: 2025-09-25 0 DAY

🎯 Recommendations:

🔍 Web Intelligence

Key Sources:

  • Cisco Security Advisory

    A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat ...