๐Ÿ”ด CVE-2025-20362

CVE-2025-20362 is a missing authorization vulnerability in Cisco ASA and FTD VPN web servers that allows unauthenticated remote attackers to access restricted URL endpoints. The vulnerability is being actively exploited in the wild and affects internet-facing firewall appliances.

โ† Back to Overview
HIGH_RISK
Risk Level
6.5
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 โ€” Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

๐Ÿ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-09-25

Added to CISA KEV: 2025-09-25 0 DAY BETWEEN CVE AND KEV

๐ŸŽฏ Recommendations:

๐Ÿ” Web Intelligence (Kagi ยท 2025-09-25)

CVE-2025-20362 is a vulnerability in Cisco Secure Firewall ASA and FTD Software that allows unauthenticated, remote attackers to access restricted URL endpoints [1]. Here's a breakdown of what is known about its exploitation:

  • Internet-facing applications or services: Yes, this vulnerability affects internet-facing applications and services.
  • Active exploitation in the wild: There is strong evidence of active exploitation in the wild.
  • Attack vectors and exploitation methods: The attack vector involves improper validation of user-supplied input to the VPN web server.
  • Targeted attacks: It has been used in targeted attacks.
  • CISA Known Exploited Vulnerabilities (KEV) status: The CISA KEV catalog indicates active exploitation of this vulnerability.
  • Technical details about internet exploitability: The vulnerability is exploited via the VPN web server due to improper validation of user-supplied input.[1]

Sources

  1. Cisco Security Advisory

    A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat ...