CVE‑2025‑20333 is a vulnerability in the VPN web server component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software allows an authenticated, remote attacker to execute arbitrary code on an affected device. The flaw results from improper validation of user-supplied input in HTTP(S) requests. With valid VPN credentials, an attacker can send crafted requests to the device and, upon successful exploitation, achieve root-level code execution — potentially leading to full device compromise.
CVE-2025-20362 is a medium-severity flaw in Cisco ASA and FTD VPN web servers that lets unauthenticated attackers access restricted URLs without authentication. With no workarounds available and exploitation attempts already observed, Cisco strongly recommends upgrading to a fixed release.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

