Cisco warned this week that two vulnerabilities, which have been used in zero-day attacks, are now being exploited to force ASA and FTD firewalls into reboot loops. The tech giant released security updates on September 25 to address the two security flaws, stating that CVE-2025-20362 enables remote threat actors to access restricted URL endpoints without authentication, while CVE-2025-20333 allows authenticated attackers to gain remote code execution on vulnerable devices. When chained, these vulnerabilities allow remote, unauthenticated attackers to gain complete control over unpatched systems. The same day, CISA issued an emergency directive ordering U.S. federal agencies to secure their Cisco firewall devices against attacks using this exploit chain within 24 hours. CISA also mandated them to disconnect ASA devices reaching their end of support (EoS) from federal organization networks. Threat monitoring service Shadowserver is currently tracking over 34,000 internet-exposed ASA and FTD instances vulnerable to CVE-2025-20333 and CVE-2025-20362 attacks, down from the nearly 50,000 unpatched firewalls it spotted in September. "Cisco previously disclosed new vulnerabilities in certain Cisco ASA 5500-X devices running Cisco Secure Firewall ASA software with VPN web services enabled, discovered in collaboration with several government agencies. We attributed these attacks to the same state-sponsored group behind the 2024 ArcaneDoor campaign and urged customers to apply the avai...
Cisco: Actively exploited firewall flaws now abused for DoS attacks
BleepingComputer
·Sergiu Gatlan
·Published Nov 7, 2025
·Updated
Affected Software
2 affected components
Cisco ASA
Cisco FTD
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses security vulnerabilities in Cisco firewalls that are being actively exploited for Denial of Service (DoS) attacks.
2
What security implications are discussed?
The vulnerabilities could cause Cisco ASA and FTD firewalls to enter reboot loops, disrupting services.
3
What products are affected by these vulnerabilities?
The vulnerabilities affect Cisco ASA and Cisco FTD firewall products.
4
What did Cisco do in response to these vulnerabilities?
Cisco released security updates on September 25 to address the identified vulnerabilities.
5
What is the potential risk if these vulnerabilities are not patched?
If not patched, these vulnerabilities could lead to successful DoS attacks, impacting network availability.