Buffer overflow in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2025-20333
Published: September 25, 2025 / Updated: April 1, 2026
Vulnerability details
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to a boundary error within the VPN Web Server when handling HTTP requests. A remote authenticated VPN user can send specially crafted HTTP requests to the affected device, trigger a buffer overflow and execute arbitrary code with root privileges.
Affected software
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2025-20333
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.85, 9.17.1.45, 9.18.4.47, 9.19.1.37, 9.20.3.7, 9.22.1.3