• News/
  • https://www.bleepingcomputer.com/news/security/cisco-actively-exploited-firewall-flaws-now-abused-for-dos-attacks/

Cisco: Actively exploited firewall flaws now abused for DoS attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Nov 7, 2025
·
Updated

Cisco warned this week that two vulnerabilities, which have been used in zero-day attacks, are now being exploited to force ASA and FTD firewalls into reboot loops. The tech giant released security updates on September 25 to address the two security flaws, stating that CVE-2025-20362 enables remote threat actors to access restricted URL endpoints without authentication, while CVE-2025-20333 allows authenticated attackers to gain remote code execution on vulnerable devices. When chained, these vulnerabilities allow remote, unauthenticated attackers to gain complete control over unpatched systems. The same day, CISA issued an emergency directive ordering U.S. federal agencies to secure their Cisco firewall devices against attacks using this exploit chain within 24 hours. CISA also mandated them to disconnect ASA devices reaching their end of support (EoS) from federal organization networks. Threat monitoring service Shadowserver is currently tracking over 34,000 internet-exposed ASA and FTD instances vulnerable to CVE-2025-20333 and CVE-2025-20362 attacks, down from the nearly 50,000 unpatched firewalls it spotted in September. "Cisco previously disclosed new vulnerabilities in certain Cisco ASA 5500-X devices running Cisco Secure Firewall ASA software with VPN web services enabled, discovered in collaboration with several government agencies. We attributed these attacks to the same state-sponsored group behind the 2024 ArcaneDoor campaign and urged customers to apply the avai...

Read full article

Affected Software

2 affected components
Cisco ASA
Cisco FTD

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses security vulnerabilities in Cisco firewalls that are being actively exploited for Denial of Service (DoS) attacks.

2

What security implications are discussed?

The vulnerabilities could cause Cisco ASA and FTD firewalls to enter reboot loops, disrupting services.

3

What products are affected by these vulnerabilities?

The vulnerabilities affect Cisco ASA and Cisco FTD firewall products.

4

What did Cisco do in response to these vulnerabilities?

Cisco released security updates on September 25 to address the identified vulnerabilities.

5

What is the potential risk if these vulnerabilities are not patched?

If not patched, these vulnerabilities could lead to successful DoS attacks, impacting network availability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203