External risk intelligence

Cisco ASA FTD IOS IOS XE IOS XR HTTP Request Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2025-20363

The vulnerability affects internet-edge infrastructure components including Cisco Secure Firewalls, ASAs, and various IOS networking platforms. These devices are designed to serve as public-facing gateways and perimeter security appliances, often exposing management or web-based services directly to the internet in standard deployment configurations.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Cisco networking and security devices that could allow an attacker to execute arbitrary code, potentially leading to a complete compromise of the affected device. This issue stems from how certain web services handle user-supplied input in HTTP requests.

  • Code execution flaw in network devices.
  • Leadership needs to know about potential device compromise.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could reach this vulnerability by sending specially crafted HTTP requests to the web services of affected Cisco devices. This could occur after an attacker gathers more system details or bypasses existing protections. Successfully exploiting this flaw allows an attacker to execute arbitrary code with root privileges, potentially leading to a full device compromise.

  • Unauthenticated or low-privilege remote access.
  • Crafted HTTP requests to web services.
  • Arbitrary code execution; complete device compromise.

Live Threat

Current exploitation, exposure, and threat context

The vulnerability could allow an attacker to execute arbitrary code on network devices. This could lead to complete compromise of the affected device, potentially impacting its functionality and any data it processes or protects.

  • Network infrastructure devices at risk.
  • Exploited via crafted HTTP requests.
  • Device compromise and potential data access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Cisco Secure Firewall and various Cisco IOS-based devices, commonly deployed as network perimeters and internet gateways. Responsibility for remediation will likely fall to infrastructure, network, and security teams. The initial step is to inventory all affected devices, determine their exposure, and confirm their business criticality to prioritize remediation efforts.

  • Infrastructure and security teams own this.
  • Verify internet-facing ASA/FTD devices first.
  • Plan maintenance for vulnerable IOS/IOS XE/XR.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the affected Cisco software used for?

This vulnerability affects Cisco Secure Firewall (ASA/FTD), Cisco IOS, IOS XE, and IOS XR. These are fundamental networking and security components. ASAs and FTDs are typically used as perimeter firewalls or VPN gateways to control traffic, while IOS and IOS XE/XR platforms are operating systems that power switches, routers, and other core network hardware that manage traffic routing and connectivity throughout an organization's internal and external networks.

What is the weakness class for CVE-2025-20363?

The weakness is classified as CWE-122, which refers to a Heap-based Buffer Overflow. In plain terms, the software fails to properly validate the size or structure of incoming data within HTTP requests. When the system processes these crafted requests, it may write more data into its memory than the allocated space allows. This corruption can eventually enable an attacker to overwrite critical memory areas and execute their own arbitrary code on the underlying device.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by sending specially crafted HTTP requests to web services running on the affected Cisco device. It is not triggered by standard network traffic or normal administrative use. Successful exploitation typically requires the attacker to have additional system information or find ways to bypass existing security mitigations first. Merely having the web service enabled does not guarantee exploitability without these specific, malicious inputs.

Why does Halo Surface Signal categorize this as external?

Halo Surface Signal identifies this as an external threat because the affected software—specifically Cisco Secure Firewalls and ASAs—are often deployed as internet-facing gateways. Because these devices are frequently positioned at the network edge to inspect or route traffic, their management or web-based services may be exposed to the internet. This placement makes them potentially accessible to remote, unauthenticated attackers who do not need to be inside your network to reach the flaw.

What is the first step for teams running these Cisco devices?

The immediate priority is to create an inventory of your Cisco networking hardware to identify which devices are running the specific vulnerable software versions. Focus your efforts on devices located at your network perimeter, as these are the most likely to be reached by remote actors. Once identified, evaluate the business criticality of these systems and coordinate with your network or infrastructure teams to plan for the necessary updates provided by the vendor.

References