Chinese hackers scanning, exploiting Cisco ASA firewalls used by governments worldwide
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20333 +1 in the same advisory: …20362 | Authenticated Buffer Overflow RCE in Cisco ASA/FTD VPN Web Server CVE-2025-20333 is a buffer overflow (CWE-120) in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software, caused by improper validation of user-supplied input in HTTP(S) requests. An attacker who already holds valid VPN user credentials can trigger it by sending crafted HTTP(S) requests to the device's VPN web interface; the flaw is remotely exploitable over the network with low attack complexity and no user interaction. A successful exploit allows arbitrary code execution as root, possibly resulting in complete compromise of the firewall or VPN gateway. Any organization running Cisco ASA or FTD software with the VPN web server enabled is affected. Exploitation is confirmed in the wild: the CVE was added to CISA's KEV on 2025-09-25, EPSS assigns a 70.7% probability of exploitation within 30 days (99th percentile), and Cisco and the UK NCSC have warned of real-world attacks (including RayInitiator and LINE VIPER malware deployment) that chain this flaw with at least one companion Cisco vulnerability. Do: Inventory all ASA/FTD devices with the VPN web server reachable by users (especially internet-exposed ones) and upgrade to the fixed releases listed in the Cisco PSIRT advisory; where patching is delayed, apply Cisco's recommended mitigations and hunt for indicators of the reported attack chain (RayInitiator/LINE VIPER). Because exploitation requires valid VPN credentials, treat VPN user credentials on affected gateways as potentially compromised and force resets. US federal agencies must follow the mitigation steps in CISA Emergency Directive 25-03 and BOD 22-01 timelines for this KEV entry. | 9.9 group max | 71% | KEV |
| mass≈100,000–300,000 internet-exposed ASA/FTD VPN web servers (order of magnitude), within a multi-million-device installed base serving large VPN user populations |
Full article646 words · extracted from therecord.media · click to collapse
China-based hackers are scanning for and exploiting a popular line of Cisco firewalls used by governments in the U.S., Europe and Asia. Incident responders from Palo Alto Networks’ Unit 42 have been tracking the targeting of Cisco Adaptive Security Appliances (ASA) — popular devices used by governments and large businesses to consolidate several different security tasks into a single appliance. In addition to acting as firewalls, the appliances also prevent some intrusions, handle spam, conduct antivirus checks and more. In a report shared with Recorded Future News, Unit 42 attributed the targeting of Cisco ASA devices to Storm-1849 — a China-based threat group that Cisco previously said has been attacking the tools since 2024. Unit 42 researchers said they saw continued Chinese targeting of Cisco ASA devices at U.S. financial institutions, defense contractors and military organizations throughout October. They noted that Storm-1849, also referred to as UAT4356, is known to target government, defense industry and financial institutions. They noted that there was a lull in activity between October 1 to October 8 — likely due to China’s Golden Week. Pete Renals, director of National Security Programs for Unit 42, said that throughout October, Storm-1849 “persisted in targeting vulnerable government edge devices.” Unit 42 saw scanning and exploitation activity targeting 12 IP addresses used by federal agencies in the U.S. They saw 11 other local and state government IP addresses targeted in October. In addition to U.S. agencies, federal government IP addresses in India, Nigeria, Japan, Norway, France, the U.K., the Netherlands, Spain, Australia, Poland, Austria, UAE, Azerbaijan and Bhutan were targeted. One month ago, the Cybersecurity and Infrastructure Security Agency (CISA) released an emergency directive ordering all federal civilian agencies to patch CVE-2025-20333 and CVE-2025-20362 — two vulnerabilities impacting Cisco ASA devices. Hackers have been seen chaining the two bugs together during attacks, according to CISA, which added that the hackers are sophisticated and have found ways to gain access to ASAs before manipulating devices so that their access persists through reboots and system upgrades. Agencies were given just one day to apply the patches and CISA officials stressed that threat actors were exploiting the bugs with “alarming ease.” Cisco said in its report on the campaign that it worked with multiple government agencies in May 2025 to investigate attacks targeting the ASA 5500-X Series devices running Cisco Secure Firewall ASA Software with VPN web services. “Despite cybersecurity advisories and emergency directives last month highlighting the critical need for patching, the actor has continued their campaigns seemingly undeterred,” Renals said. “While groups like Salt and Volt Typhoon remain an active threat, newer groups like Storm-1849… are quickly expanding their operations and gaining global prominence." CISA did not attribute the exploitation of the bugs but tied it to the same nation-state hackers behind the ArcaneDoor campaign discovered last year. CISA and Cisco declined to formally attribute the 2025 campaign to Chinese actors but cybersecurity research firm Censys investigated actor-controlled IPs tied to the 2024 ArcaneDoor campaign and found data “suggesting the potential involvement of an actor based in China, including links to multiple major Chinese networks and the presence of Chinese-developed anti-censorship software.” CISA and Cisco did not respond to requests for comment.
No previous article
No new articles
Martin Matishak
is the senior cybersecurity reporter for The Record. Prior to joining Recorded Future News in 2021, he spent more than five years at Politico, where he covered digital and national security developments across Capitol Hill, the Pentagon and the U.S. intelligence community. He previously was a reporter at The Hill, National Journal Group and Inside Washington Publishers.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/chinese-hackers-scan-exploit-firewalls-government