Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Cisco Vulnerability Let Remote Attackers Execute Arbitrary Code on Firewalls and Routers

Critical Cisco Vulnerability Let Remote Attackers Execute Arbitrary Code on Firewalls and Routers

Posted on September 26, 2025September 26, 2025 By CWS

Cisco warns of a Crucial distant code execution flaw in internet companies throughout a number of Cisco platforms.  Tracked as CVE-2025-20363 (CWE-122), this vulnerability carries a CVSS 3.1 Base Rating of 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) and impacts ASA, FTD, IOS, IOS XE, and IOS XR Software program.

Cisco Enter Validation Flaw (CVE-2025-20363)

The flaw stems from improper validation of user-supplied enter in HTTP requests. Attackers can craft malicious HTTP packets to bypass exploit mitigations and execute arbitrary shell instructions as root. 

For Cisco Safe Firewall ASA and FTD, no authentication is required; for IOS, IOS XE, and IOS XR, solely low-privileged authenticated entry is required.

Affected companies pay attention on SSL or HTTP ports when options corresponding to webvpn, AnyConnect SSL VPN, or the HTTP server are enabled. Instance CLI checks:

Profitable exploitation yields a root shell, probably resulting in full gadget compromise. 

Cisco acknowledges Keane O’Kelley of Cisco ASIG for locating the defect. Coordination with ASD, CSE, NCSC, and CISA contributed to the advisory.

All ASA Sequence (5500-X, ASAv, Firepower 1000/2100/4100/9000, Safe Firewall 1200/3100/4200), FTD platforms, IOS routers with SSL VPN, IOS XE routers, and ASR 9001 operating 32-bit IOS XR with HTTP enabled are susceptible. 

No workarounds exist. Prospects should improve to fastened releases instantly. The advisory gives detailed fastened variations per platform below the Fastened Software program part.

Threat FactorsDetailsAffected ProductsCisco Safe Firewall ASA & FTD Software program, Cisco IOS Software program & IOS XE Software program, Cisco IOS XR Software program (32-bit on ASR 9001 with HTTP server enabled)ImpactRemote unauthenticated code execution as rootExploit PrerequisitesSSL VPN (webvpn) or AnyConnect SSL VPN enabledCVSS 3.1 Score9.0 (Crucial)

Cisco recommends utilizing the Cisco Software program Checker to establish susceptible releases and the earliest patches. Directors ought to audit gadget configurations to verify SSL VPN or HTTP server standing. 

For ASA/FTD, confirm webvpn or AnyConnect SSL VPN settings; for IOS XR, guarantee run uname -s returns Linux or disable HTTP through no http server. Cisco PSIRT confirms no energetic exploitation within the wild.

Comply with us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Arbitrary, Attackers, Cisco, Code, Critical, Execute, Firewalls, Remote, Routers, Vulnerability

Post navigation

Previous Post: Hackers Exploiting Cisco ASA Zero-Day to Deploy RayInitiator and LINE VIPER Malware
Next Post: Recent Fortra GoAnywhere MFT Vulnerability Exploited as Zero-Day

Related Posts

Patch for Code Execution Vulnerabilities in Endpoint Manager Patch for Code Execution Vulnerabilities in Endpoint Manager Cyber Security News
CamelClone Espionage Targets Governments via File-Sharing CamelClone Espionage Targets Governments via File-Sharing Cyber Security News
Vulnerable Codes in Legacy Python Packages Enables Attacks on Python Package Index Via Domain Compromise Vulnerable Codes in Legacy Python Packages Enables Attacks on Python Package Index Via Domain Compromise Cyber Security News
Hackers Attacking Apache Tomcat Manager From 400 Unique IPs Hackers Attacking Apache Tomcat Manager From 400 Unique IPs Cyber Security News
Record-Breaking 15 Tbps DDoS Attack From 500,000+ Devices Hits Azure Network Record-Breaking 15 Tbps DDoS Attack From 500,000+ Devices Hits Azure Network Cyber Security News
Cisco AnyConnect VPN Server Vulnerability Let Attackers Trigger DoS Attack Cisco AnyConnect VPN Server Vulnerability Let Attackers Trigger DoS Attack Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hundreds of Fake VPN Extensions Divert Browser Traffic
  • Critical VMware vCenter Vulnerability Exploited by Hackers
  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hundreds of Fake VPN Extensions Divert Browser Traffic
  • Critical VMware vCenter Vulnerability Exploited by Hackers
  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark