CVE-2025-20237
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2025-20237 is an authenticated command injection vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software that allows an authenticated, local attacker with valid administrative credentials to execute arbitrary commands on the underlying operating system with root-level privileges. The vulnerability affects Cisco Secure Firewall ASA and FTD Software across a wide range of versions, regardless of device configuration; Cisco Secure Firewall Management Center (FMC) Software is not affected. It was disclosed on August 14, 2025, as part of Cisco's August 2025 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. The CVSS v3.1 base score is 6.0 (Medium) (Cisco Advisory).

Technical details

The root cause is insufficient input validation of user-supplied commands, classified as CWE-146 (Improper Neutralization of Expression/Command Delimiters) and also associated with CWE-78 (OS Command Injection). An attacker exploits this by authenticating to a vulnerable ASA or FTD device with administrative credentials and submitting crafted input to specific CLI commands, causing the underlying operating system to execute attacker-controlled commands as root. The attack vector is local (AV:L), requires high privileges (PR:H), and no user interaction, with no workarounds available. The vulnerability was discovered internally by T.VE of Cisco's Advanced Security Initiatives Group (ASIG) (Cisco Advisory).

Impact

Successful exploitation allows an authenticated administrative attacker to execute arbitrary OS commands as root on the affected Cisco ASA or FTD device, resulting in high confidentiality and integrity impact (C:H, I:H) with no direct availability impact per the CVSS scoring. An attacker with root-level access could read sensitive configuration data, credentials, or cryptographic material stored on the device, modify firewall rules or system files, and potentially use the compromised device as a pivot point for lateral movement within the network. Given that ASA and FTD devices are typically deployed as network security perimeters, compromise could expose the entire protected network (Cisco Advisory).

Exploitability

As of the advisory publication date, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild. No public proof-of-concept exploit code has been identified. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid administrative credentials and local access, significantly limiting the attacker pool (Cisco Advisory).

Exploitation steps

  1. Credential Acquisition: Obtain valid administrative credentials for a target Cisco ASA or FTD device through phishing, credential theft, or insider access — exploitation requires high-privilege local authentication.
  2. Authentication: Log in to the device via the CLI (SSH, console, or Telnet if enabled) using the acquired administrative credentials.
  3. Identify Vulnerable Commands: Enumerate specific CLI commands that are susceptible to command delimiter injection (the exact commands are not publicly disclosed by Cisco).
  4. Craft Malicious Input: Construct input containing OS command delimiters or special characters (e.g., ;, |, $()) designed to break out of the expected command context and inject arbitrary OS commands.
  5. Execute Payload: Submit the crafted input to the vulnerable command, causing the underlying OS to execute the injected commands with root privileges.
  6. Post-Exploitation: With root access, exfiltrate configuration data, install persistent backdoors, modify firewall policies, or use the device as a pivot point for further network compromise (Cisco Advisory).

Indicators of compromise

  • Logs: Unexpected or anomalous CLI command entries in ASA/FTD syslog or audit logs, particularly commands containing shell metacharacters (;, |, &&, $(), backticks) in administrative sessions.
  • Logs: Authentication events for administrative accounts at unusual times or from unexpected source IPs, especially preceding suspicious command execution.
  • Process/System: Unexpected processes running as root on the ASA/FTD device that are not part of normal Cisco software operations.
  • File System: Unauthorized modifications to system files, firewall configuration, or the presence of new files (e.g., scripts, binaries) in non-standard directories on the device.
  • Network: Unusual outbound connections from the ASA/FTD management interface to external IPs, which may indicate data exfiltration or C2 communication following exploitation.

Mitigation and workarounds

Cisco has released software updates that address CVE-2025-20237. There are no workarounds available for this vulnerability. Administrators should use the Cisco Software Checker to identify the earliest fixed release for their specific ASA or FTD software version and platform, and upgrade as soon as possible. As a defense-in-depth measure, restrict administrative access to ASA/FTD devices to trusted management networks and enforce multi-factor authentication for administrative accounts to reduce the risk of credential compromise (Cisco Advisory).

Community reactions

The vulnerability was part of Cisco's August 2025 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication, which attracted coverage from security news outlets noting that multiple critical and medium vulnerabilities were disclosed simultaneously affecting Cisco firewall products (Undercode News). The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Cisco security products could allow for arbitrary code execution (CIS Advisory). Community reaction has been measured given the requirement for administrative credentials, which limits the practical exploitability compared to unauthenticated vulnerabilities in the same product family.

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20349HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
YesYesAug 11, 2026
CVE-2026-20012HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesMar 25, 2026
CVE-2026-20025MEDIUM6.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20023MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20024MEDIUM5.7
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management