• News/
  • https://www.bleepingcomputer.com/news/security/nearly-50-000-cisco-firewalls-vulnerable-to-actively-exploited-flaws/

Nearly 50,000 Cisco firewalls vulnerable to actively exploited flaws

BleepingComputer
·
Bill Toulas
·
Published Sep 30, 2025
·
Updated

Roughly 50,000 Cisco Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) appliances exposed on the public web are vulnerable to two vulnerabilities actively leveraged by hackers. The flaws, tracked as CVE-2025-20333 and CVE-2025-20362, enable arbitrary code execution and access to restricted URL endpoints associated with VPN access. Both security issues can be exploited remotely without authentication. On September 25, Cisco warned that the issues were actively exploited in attacks that started before patches were available to customers. No workarounds exist for either flaw, but temporary hardening steps could include restricting VPN web interface exposure and increasing logging and monitoring for suspicious VPN logins and crafted HTTP requests. Today, threat monitoring service The Shadowserver Foundation reports that its scans discoveredmore than 48,800 internet-exposed ASA and FTD instances that are still vulnerable to CVE-2025-20333 and CVE-2025-20362. Most of the IPs are located in the United States (more than 19,200 endpoints), followed by the United Kingdom (2,800), Japan (2,300), Germany (2,200), Russia (2,100), Canada (1,500), and Denmark (1,200). These figures are as of yesterday, September 29, indicating a lack of appropriate response to the ongoing exploitation activity, as well as previous warnings. Notably, Greynoise had warned on September 4 about suspicious scans that occurred as early as late August, targeting Cisco ASA devices. In 80% of the ...

Read full article

Affected Software

2 affected components
Cisco Adaptive Security Appliance
Cisco Firewall Threat Defense

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses nearly 50,000 Cisco firewalls being vulnerable to actively exploited security flaws.

2

What vulnerabilities are affecting Cisco firewalls?

The vulnerabilities are tracked as CVE-2025-2033 and CVE-2025-2034, which are being actively leveraged by hackers.

3

How many Cisco devices are exposed on the public web?

Approximately 50,000 Cisco Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) devices are exposed.

4

What are the security implications of these vulnerabilities?

The exploitation of these vulnerabilities can lead to unauthorized access and potential breaches in network security.

5

Which Cisco products are affected by these vulnerabilities?

The affected products include Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203