VORANT. Threat Intelligence Sign in Get the full feed

Cisco patches RCE flaw in Firewall Management Center

critical vulnerability government-nationalfinancial-serviceshealthcareenergytelecommunicationsinfrastructure

Cisco released patches for multiple vulnerabilities in its security products, including a critical unauthenticated remote code execution flaw in Secure Firewall Management Center.

Cisco has disclosed multiple vulnerabilities affecting its security product portfolio, including Secure Firewall Management Center, Firepower devices, ASA Software, Firewall Threat Defense, Identity Services Engine, and IOS/IOS XE platforms. The most severe vulnerability (CVE-2025-20265) allows unauthenticated remote attackers to inject arbitrary shell commands into Cisco Secure Firewall Management Center through the RADIUS subsystem, potentially leading to full system compromise.

The advisory encompasses over 30 vulnerabilities ranging from denial-of-service conditions to authentication bypasses and privilege escalation issues. Many affect the web-based management interfaces and VPN services across Cisco's firewall and threat defense products. Multiple IKEv2 implementation flaws could enable DoS attacks against IOS, IOS XE, ASA, and FTD platforms. Additional vulnerabilities involve packet inspection engines, certificate processing, NAT DNS inspection, and TLS 1.3 implementation weaknesses.

Cisco has not observed active exploitation of these vulnerabilities in the wild. The affected systems span multiple product versions, with exploitation dependent on specific configuration criteria rather than version numbers alone. Organizations are strongly advised to review Cisco's configuration guidance to determine exposure and apply available patches immediately after testing. The vulnerabilities primarily impact enterprise networks, government agencies, and critical infrastructure sectors relying on Cisco security infrastructure.

Mentioned in this report

Vulnerabilities CVE-2025-20127CVE-2025-20133CVE-2025-20134CVE-2025-20135CVE-2025-20136CVE-2025-20148CVE-2025-20217CVE-2025-20218CVE-2025-20219CVE-2025-20220CVE-2025-20222CVE-2025-20224CVE-2025-20225CVE-2025-20235CVE-2025-20237CVE-2025-20238CVE-2025-20239CVE-2025-20243CVE-2025-20244CVE-2025-20251CVE-2025-20252CVE-2025-20253CVE-2025-20254CVE-2025-20263CVE-2025-20265CVE-2025-20268CVE-2025-20301CVE-2025-20302CVE-2025-20306

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-cisco-security-products-could-allow-for-arbitrary-code-execution_2025-073

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free