
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20237 is an authenticated command injection vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software that allows an authenticated, local attacker with valid administrative credentials to execute arbitrary commands on the underlying operating system with root-level privileges. The vulnerability affects Cisco Secure Firewall ASA and FTD Software across a wide range of versions, regardless of device configuration; Cisco Secure Firewall Management Center (FMC) Software is not affected. It was disclosed on August 14, 2025, as part of Cisco's August 2025 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. The CVSS v3.1 base score is 6.0 (Medium) (Cisco Advisory).
The root cause is insufficient input validation of user-supplied commands, classified as CWE-146 (Improper Neutralization of Expression/Command Delimiters) and also associated with CWE-78 (OS Command Injection). An attacker exploits this by authenticating to a vulnerable ASA or FTD device with administrative credentials and submitting crafted input to specific CLI commands, causing the underlying operating system to execute attacker-controlled commands as root. The attack vector is local (AV:L), requires high privileges (PR:H), and no user interaction, with no workarounds available. The vulnerability was discovered internally by T.VE of Cisco's Advanced Security Initiatives Group (ASIG) (Cisco Advisory).
Successful exploitation allows an authenticated administrative attacker to execute arbitrary OS commands as root on the affected Cisco ASA or FTD device, resulting in high confidentiality and integrity impact (C:H, I:H) with no direct availability impact per the CVSS scoring. An attacker with root-level access could read sensitive configuration data, credentials, or cryptographic material stored on the device, modify firewall rules or system files, and potentially use the compromised device as a pivot point for lateral movement within the network. Given that ASA and FTD devices are typically deployed as network security perimeters, compromise could expose the entire protected network (Cisco Advisory).
As of the advisory publication date, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild. No public proof-of-concept exploit code has been identified. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid administrative credentials and local access, significantly limiting the attacker pool (Cisco Advisory).
;, |, $()) designed to break out of the expected command context and inject arbitrary OS commands.;, |, &&, $(), backticks) in administrative sessions.Cisco has released software updates that address CVE-2025-20237. There are no workarounds available for this vulnerability. Administrators should use the Cisco Software Checker to identify the earliest fixed release for their specific ASA or FTD software version and platform, and upgrade as soon as possible. As a defense-in-depth measure, restrict administrative access to ASA/FTD devices to trusted management networks and enforce multi-factor authentication for administrative accounts to reduce the risk of credential compromise (Cisco Advisory).
The vulnerability was part of Cisco's August 2025 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication, which attracted coverage from security news outlets noting that multiple critical and medium vulnerabilities were disclosed simultaneously affecting Cisco firewall products (Undercode News). The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Cisco security products could allow for arbitrary code execution (CIS Advisory). Community reaction has been measured given the requirement for administrative credentials, which limits the practical exploitability compared to unauthenticated vulnerabilities in the same product family.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."