A sweeping wave of cyber-espionage activity is targeting one of the world’s most widely deployed firewall platforms. Infrastructure Security Agency (CISA) has issued an emergency directive in response to active exploitation of critical zero-day vulnerabilities in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) products. The campaign is attributed to a sophisticated threat group and represents a stark reminder of how internet-edge devices remain high-value targets for state-aligned adversaries.

Zero-Days Under Attack
Two key vulnerabilities — tracked as CVE‑2025‑20333 and CVE‑2025‑20362 — are reported to be under active exploitation by adversaries. According to vendor and independent advisories these flaws impact Cisco ASA and FTD software, allowing remote code execution and unauthorized access to restricted web-VPN endpoints.

CVE-2025-20333 is especially severe: an authenticated attacker with valid VPN credentials could execute arbitrary code with root privileges, potentially taking complete control of the appliance. Meanwhile, CVE-2025-20362 enables unauthenticated access to normally restricted URL endpoints and is believed to be chained with the former to achieve device compromise.

The scale of exposure is sizeable: as of late September 2025, security researchers reported nearly 50,000 internet-connected Cisco ASA/FTD devices remained unpatched and vulnerable.

Background Context

Cisco’s ASA and FTD platforms serve as key perimeter security appliances in many enterprise and government networks, managing VPN access, firewalling and web-VPN services. The threat actor behind this wave is identified by Cisco as UAT4356, and by Microsoft as Storm-1849 — a group linked to the earlier “ArcaneDoor” campaign of 2024.

Attackers reportedly targeted soon-to-be end-of-support ASA 5500-X series hardware lacking Secure Boot and Trust Anchor protections, a factor enabling firmware and ROM-level persistence. Notably, the U.K. national cyber authority (National Cyber Security Centre, NCSC) published analysis of two malware families tied to the campaign — “RayInitiator” (bootkit) and “LINE VIPER” (modular shellcode loader) — capable of surviving reboots and firmware upgrades.

Expert Insights & Response
CISA issued its Emergency Directive 25-03 requiring U.S. federal civilian agencies to identify, isolate and remediate compromised devices, or remove them from network operation entirely. According to cybersecurity firm Tenable, the active exploitation of these zero-days represents “a direct route to full device compromise” and urges immediate patching and forensic investigation.

In practical terms, organizations are advised to inventory all ASA/FTD devices, apply the fixes released by Cisco, hunt for signs of compromise (such as altered ROM/firmware, disabled logging, or unexpected reboots), reset credentials, and rebuild devices if persistence is suspected. Analysts warn that the combination of edge device compromise, firmware-level implant techniques and public exposure makes this campaign uniquely dangerous: a successful attacker at the firewall stage undermines traditional network segmentation and detection layers.

Conclusion
The unfolding campaign exploiting Cisco ASA/FTD zero-days underscores a hard lesson for cybersecurity teams: perimeter devices may appear hardened, but when vulnerable firmware meets a sophisticated threat actor — the consequences can be catastrophic. With tens of thousands of exposed devices still operational worldwide, and national-level directives in motion, the message is clear: patch early, hunt thoroughly, and treat edge devices as high-value targets. As defenders sprint to catch up, the attackers appear to have gained precious lead time — reminding every organisation that in cybersecurity, instability often begins at the edge.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *