CVE-2025-20363

ENISA EUVD: EUVD-2025-31138 ↗
✓ Confirmed 0-Day
Triaged: March 5, 2026 4 articles Published: 2025-09-25

EPSS Score

Source: FIRST.org · 2026-05-23
6.44%
probability
This CVE has a 6.44% probability of being exploited in the next 30 days.
0% Top 91.2th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
9
CRITICAL
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

VulnerabilityLookup (CNA)
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privileges to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web service on an affected device after obtaining additional information about the system, overcoming exploit mitigations, or both. A successful exploit could allow the attacker to execute arbitrary code as root, which may lead to the complete compromise of the affected device. For more information about this vulnerability, see the Details ["#details"] section of this advisory.

Affected Products

Cisco
IOS
12.2(15)B 12.2(16)B1 12.2(16)B2 12.2(16)B 12.2(15)BC2a 12.2(15)BC1a
Cisco
Cisco IOS XR Software
6.5.1 6.5.2 6.5.3 6.6.2 6.6.3 6.6.25
Cisco
Cisco Adaptive Security Appliance (ASA) Software
9.8.1 9.8.1.5 9.8.1.7 9.8.2 9.8.2.8 9.8.2.14
Cisco
Cisco IOS XE Software
3.2.0SG 3.2.1SG 3.2.2SG 3.2.3SG 3.2.4SG 3.2.5SG
Cisco
Cisco Firepower Threat Defense Software
6.2.3 6.2.3.1 6.2.3.2 6.2.3.3 6.2.3.4 6.2.3.5

Attack Intelligence

Signal Intelligence

Confidence
85%
EPSS 6.44%
CVSS v3.1 9
Mentions 4
Last Seen Sep 26, 2025

CNA Information

CNA Assigner
cisco

Analyst Note

CVE-2025-20363 is explicitly named as a zero-day in Cisco warnings and CISA orders to patch, with active exploitation confirmed in attacks. Published September 2025 with immediate exploitation reports, meeting the zero-day criteria of exploitation before or simultaneous with patch availability.

Threat Actors 10

APT 28
apt_group Information theft and espionage 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
GCHQ
apt_group Information theft and espionage 🇬🇧 GB
ArcaneDoor
apt_group 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
The White Company
apt_group Information theft and espionage 🇨🇳 CN
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 05, 2026
Published DateSep 25, 2025