On September 25, 2025, Cisco disclosed two vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software, CVE-2025-20333 and CVE-2025-20362, and confirmed that a sophisticated state-sponsored group was already chaining them together in the wild. The same day, CISA issued Emergency Directive 25-03, giving US federal agencies roughly 24 hours to collect forensic data and patch.
If your organization uses Cisco ASA or Firepower devices for VPN or perimeter defense, this is not a federal-only problem. The same devices sit at the edge of thousands of private networks, and the attackers behind this campaign were modifying device firmware to survive reboots and upgrades. This article explains what the flaws do, who was exploiting them, and what to do.
What the two vulnerabilities do
Both flaws are in the VPN web server component of ASA and FTD software, the service that handles remote-access VPN connections.
- CVE-2025-20333 (CVSS 9.9) is a remote code execution flaw caused by improper validation of user input. On its own, it requires valid VPN credentials, but a successful attacker can run arbitrary code as root.
- CVE-2025-20362 (CVSS 6.5) is a missing-authorization flaw that lets an unauthenticated attacker reach restricted URL endpoints that should require login.
The danger is in the combination. The authorization bypass removes the credential requirement from the code execution flaw, so chained together they give a remote, unauthenticated attacker full control of an internet-facing firewall. Cisco disclosed a third, related flaw at the same time, CVE-2025-20363, which it rated critical but did not report as exploited.
Who was exploiting them, and how
Cisco and CISA linked the activity to ArcaneDoor, an espionage campaign first identified in early 2024 that Cisco tracks as UAT4356. The group specifically targets network perimeter devices, which are attractive because they sit outside most endpoint monitoring and see all traffic in and out of a network.
What made this campaign unusually serious was persistence. On older ASA 5500-X series models that lack Secure Boot, the attackers modified ROMMON, the device’s low-level boot firmware, so their access survived reboots and software upgrades. The UK’s National Cyber Security Centre published analysis of the implants involved, a bootkit it named RayInitiator and a shellcode loader named LINE VIPER. Cisco also reported that the attackers disabled logging, intercepted CLI commands and deliberately crashed devices to frustrate diagnostic analysis.
The practical implication: on affected models, patching alone may not remove an attacker who was already in. Devices that may have been compromised need forensic checks, and in some cases a firmware reimage or replacement.
What CISA’s emergency directive required
Emergency directives are rare, and ED 25-03 was blunt. Federal agencies had to identify every ASA and Firepower device; collect core dumps from public-facing ASA hardware and submit them to CISA; apply Cisco’s updates to supported devices by 11:59 p.m. EDT on September 26, 2025; and permanently disconnect devices reaching end of support on or before September 30, 2025. Agencies were also told to apply future updates within 48 hours of release and report a full inventory by October 2.
Private organizations are not bound by the directive, but it is a useful benchmark. When the federal government gives its own agencies one day, it is signaling how quickly it expects attackers to move. We discuss that shift in Is Your Organization Prepared for Stricter Patch Deadlines?
What to do if you run Cisco ASA or Firepower
- Inventory every device, including backup units, branch firewalls and virtual ASAv instances, and record model, software version and support status.
- Upgrade to a fixed release using Cisco’s advisory and software checker to confirm the minimum version for your train. Verify the running version afterward, not just that an update was attempted.
- Check for compromise. Follow Cisco’s and CISA’s detection guidance, especially on ASA 5500-X models without Secure Boot. If indicators appear, treat it as an incident and engage responders before rebooting or reimaging, so evidence is preserved.
- Retire end-of-support hardware. Devices that no longer receive fixes cannot be made safe at the perimeter.
- Reduce exposure. Restrict management interfaces to internal networks, and review whether the VPN web portal needs to be internet-facing at all.
- Reset credentials and review logs for VPN and administrative accounts, since a compromised firewall may have exposed them.
- Send firewall logs off the device to a central system, so an attacker who tampers with local logging cannot erase the record.
The trade-off is downtime. Firewall upgrades and reimages interrupt connectivity, and many small organizations have a single device with no failover. Plan a maintenance window now, and if you rely on one firewall, this is a good moment to budget for a high-availability pair.
The bigger lesson: edge devices are prime targets
Firewalls, VPN gateways and other edge appliances have become a favorite target for state-backed and criminal groups alike. They are internet-facing by design, often run older software, rarely support endpoint detection tools, and grant broad network access when compromised. Treat them as your highest-priority patching tier, monitor them from outside the device, and plan replacement before end of support rather than after. Our overview of zero-days and critical vulnerabilities covers how to build that process.
Update (September 2026): The story did not end with the first patch. In November 2025 Cisco warned of a new attack variant that could make unpatched ASA and FTD devices reload unexpectedly, and CISA updated its guidance after finding that some agencies believed they had patched but were still running vulnerable versions. The lesson stands: confirm the running version against the minimum fixed release, not just that an update was applied.
Frequently asked questions
Are we affected if we do not use Cisco’s remote-access VPN?
The vulnerable component is the VPN web server, so exposure depends on which features are enabled. Check Cisco’s advisory for the affected configurations, and patch regardless, since configurations change over time.
Is patching enough?
Not if the device was already compromised. On older models, attackers modified boot firmware to persist through upgrades, so compromise assessment is essential for any exposed device.
We are a small business. Would a nation-state really target us?
Perhaps not directly, but once exploitation techniques become public, criminal groups scan the entire internet for vulnerable devices. Size offers no protection against automated scanning.
Get help securing your perimeter
Delana Technologies helps organizations inventory and patch edge devices, assess them for compromise, and plan replacements through our cybersecurity and compliance services. If you run Cisco ASA or Firepower and need a second set of eyes, call 239.414.5126 or contact us.
Sources: Cisco Security Advisories for CVE-2025-20333 and CVE-2025-20362 (September 25, 2025) and “Continued Attacks Against Cisco Firewalls” guidance; CISA Emergency Directive 25-03 (September 25, 2025) and November 2025 implementation update; UK National Cyber Security Centre malware analysis of RayInitiator and LINE VIPER (September 2025); Help Net Security and BleepingComputer reporting (November 2025).
