Skip to content

Chinese Threat Actors Continue To Scan & Exploit Cisco ASA Firewalls Worldwide

Linkedin • November 2, 2025

In recent weeks, a sophisticated cyber-espionage campaign has come into sharper focus: a China-linked hacking group has been actively scanning for and exploiting unpatched firewalls from Cisco—specifically its Adaptive Security Appliance (ASA) line—widely deployed across governments, defence institutions and large enterprises around the world.

According to incident response analysts at Palo Alto Networks’ Unit 42, the group known as Storm‑1849 (also tracked as UAT4356) has been targeting ASA devices in the U.S., Europe and Asia throughout October. These firewalls—commonly used at government and large-enterprise “edge” networks—combine firewalling, intrusion prevention, VPN services, antivirus and spam filtering in one appliance, making them a high-value target.

Unit 42 reports that in October alone they observed scanning and exploitation attempts against 12 IP addresses tied to U.S. federal agencies, and another 11 linked to state or local government entities. The campaign is by no means limited to the U.S.: public‐facing IPs in India, Nigeria, Japan, Norway, France, the U.K., the Netherlands, Spain, Australia, Poland, Austria, UAE, Azerbaijan and Bhutan were also targeted.

At the heart of the campaign are two critical zero‐day vulnerabilities in Cisco ASA and its companion product, Cisco Secure Firewall Threat Defense (FTD). These are:

CVE‑2025‑20333 : a buffer‐overflow in the VPN Web Server component of the ASA/FTD software, rated CVSS 9.9 and exploited in the wild. The vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of the affected device.

CVE‑2025‑20362 : a missing-authorization flaw in the same WebVPN interface, with CVSS 6.5, which can be chained with the above to achieve full device compromise. The vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to access restricted URL endpoints that are related to remote access VPN that should otherwise be inaccessible without authentication. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web server on a device. A successful exploit could allow the attacker to access a restricted URL without authentication.

Cisco has confirmed that these vulnerabilities have been actively used by threat actors, and that part of the attack chain involves persistence mechanisms which survive reboots and upgrades (for example, boot-kits that modify ROMMON) on affected devices. All of this prompted the Cybersecurity and Infrastructure Security Agency (CISA) in the U.S. to issue an Emergency Directive (ED 25-03) ordering federal civilian agencies to identify and mitigate potential compromise of Cisco devices.

(Use these when triaging ASA/FTD devices and the networks they protect)

Device / local artefacts

disk0:/firmware_update.log present or recently modified (presence after patch may indicate prior tampering). Unexpected or modified ROMMON/boot variables, unexpected boot images, or mismatch between firmware version and installed boot sectors. Unexpected processes or in-memory modules seen during a core dump / memory capture (signs of LINE VIPER / RayInitiator-style implants). Suppressed syslog events, gaps in syslog timelines, or corruption of log files.

Network / traffic indicators

Large or unusual VPN session creations from new remote IPs or patterns (especially to administrative/VPN web endpoints) soon after scanning spikes. Outbound connections from ASA management plane to unexpected external IPs/domains — especially over uncommon ports or encrypted tunnels initiated from the device itself.

Behavioural indicators

Device reboots that correlate with attempted upgrades but where configuration or credentials later differ. Administrative accounts created/modified without formal change control. Unexpected CPU/memory usage spikes in ASA process space (WebVPN)

Edge firewalls such as the ASA line present attractive targets for spying actors. They sit at the boundary between internal networks and the internet, and if compromised they offer access to high-value traffic, credentials and internal systems. They also tend to be less frequently patched than more visible assets, particularly when deployed by government agencies under heavy operational constraints. One blog noted that some of the targeted ASA models were nearing or past end-of-support dates (EoS), and lacked “Secure Boot” or “Trust Anchor” protections.

Moreover, the fact that the vulnerabilities impact the WebVPN interface—which is often exposed externally to allow remote access—makes them particularly exploitable at scale. Attack chains observed include scanning for internet‐facing ASA devices, exploiting CVE-2025-20362 to bypass authentication, then exploiting CVE-2025-20333 to achieve root code execution, followed by implanting a bootkit (RayInitiator) and modular shellcode loader (LINE VIPER) to maintain persistence and exfiltrate data.

Attribution and significance Unit 42 attributes this activity to Storm-1849, a group which Cisco and other security researchers link to “ArcaneDoor” campaigns that began in 2024. Although neither CISA nor Cisco have formally attributed the 2025 campaign to Chinese state actors, publicly available investigations (e.g., from Censys) found actor-controlled IPs tied to Chinese networks, and evidence of Chinese-developed anti-censorship tools in the control infrastructure. The scale, sophistication and targeting of this campaign suggest espionage motives—governments, defence contractors, financial institutions—rather than purely financial gain.

Global scope and consequences The public data suggest this campaign is well-globalised. The number of exposed vulnerable devices is startling: one estimate placed around 50,000 internet‐connected Cisco ASA/FTD devices still unpatched for these vulnerabilities as of late September 2025—nearly 20,000 of them in the U.S., with the U.K., Germany and other western countries also heavily impacted. The global nature of the campaign means that the compromise of even a single firewall in a less-resourced jurisdiction could yield access to broad networks, regional backdoors or chain-of-trust attacks.

For every security team in government, defence, critical infrastructure or enterprise it's a stark reminder: vulnerabilities at the edge devices can provide direct access to high-value assets. The fact that attackers are combining authentication bypasses with deep persistence measures that survive firmware upgrades underscores how much the firewall stacks—which traditionally have been considered stable and less volatile—are now a frontline for advanced threat actors.

Conduct an inventory of all externally-facing ASA/FTD devices (and any equivalent firewall/VPN appliances). Determine if they are running vulnerable versions (e.g., ASA Software 9.12, 9.14, 9.16-9.20, 9.22-9.23; FTD 7.0-7.7) as per vendor advisories. Apply the latest patches immediately . Cisco has released fixed versions to remediate CVE-2025-20333 and CVE-2025-20362 and recommends migration. If patching cannot be immediate: restrict or disable SSL VPN/WebVPN services, isolate or remove vulnerable devices from internet-exposure, monitor for abnormal VPN logins and crafted HTTP/HTTPS requests. Conduct forensic investigations: check for indicators of compromise such as modification of firmware_update.log, unexpected reboot logs, suppression of syslog events, CLI command interception and other anomalies. Post-upgrade: reset devices to factory default where compromise is suspected, regenerate credentials, certificates and keys, and ensure that persistent implants are removed from boot/firmware modules. Consider architectural implications: edge firewall/VPN appliances may require higher priority in vulnerability management programmes, shrinking the time from disclosure to patching. Consider migration towards zero-trust models where possible.

What we’re seeing is not a simple mass scanning campaign. The targeting, scaling, chaining of zero-days and implanting of permanent persistence mechanisms all point to a mature, state- actor doing reconnaissance and no doubt inserting footholds in critical infrastructure globally. For any organisation relying on Cisco ASA/FTD appliances—particularly government or critical-infrastructure sectors—the message is urgent: patch now, assume compromise, hunt actively, and treat firewall gear not as “just plumbing” but as a strategic vulnerability.

🎃👻💀 This Halloween we expose the Application Haunted House 👇🏻