Roughly 50,000 Cisco Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) appliances exposed on the public web are vulnerable to two vulnerabilities actively leveraged by hackers. The flaws, tracked as CVE-2025-20333 and CVE-2025-20362, enable arbitrary code execution and access to restricted URL endpoints associated with VPN access. Both security issues can be exploited remotely without authentication. On September 25, Cisco warned that the issues were actively exploited in attacks that started before patches were available to customers. No workarounds exist for either flaw, but temporary hardening steps could include restricting VPN web interface exposure and increasing logging and monitoring for suspicious VPN logins and crafted HTTP requests. Today, threat monitoring service The Shadowserver Foundation reports that its scans discoveredmore than 48,800 internet-exposed ASA and FTD instances that are still vulnerable to CVE-2025-20333 and CVE-2025-20362. Most of the IPs are located in the United States (more than 19,200 endpoints), followed by the United Kingdom (2,800), Japan (2,300), Germany (2,200), Russia (2,100), Canada (1,500), and Denmark (1,200). These figures are as of yesterday, September 29, indicating a lack of appropriate response to the ongoing exploitation activity, as well as previous warnings. Notably, Greynoise had warned on September 4 about suspicious scans that occurred as early as late August, targeting Cisco ASA devices. In 80% of the ...
Nearly 50,000 Cisco firewalls vulnerable to actively exploited flaws
BleepingComputer
·Bill Toulas
·Published Sep 30, 2025
·Updated
Affected Software
2 affected components
Cisco Adaptive Security Appliance
Cisco Firewall Threat Defense
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses nearly 50,000 Cisco firewalls being vulnerable to actively exploited security flaws.
2
What vulnerabilities are affecting Cisco firewalls?
The vulnerabilities are tracked as CVE-2025-2033 and CVE-2025-2034, which are being actively leveraged by hackers.
3
How many Cisco devices are exposed on the public web?
Approximately 50,000 Cisco Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) devices are exposed.
4
What are the security implications of these vulnerabilities?
The exploitation of these vulnerabilities can lead to unauthorized access and potential breaches in network security.
5
Which Cisco products are affected by these vulnerabilities?
The affected products include Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD).