Cisco ASA and FTD devices can stay compromised after the patch lands. The standard response — fix the CVEs and move on — misses that FIRESTARTER can remain active and let attackers come back without re-exploiting the original flaw.
CISA and the UK NCSC say FIRESTARTER is tied to a widespread campaign that used CVE-2025-20333 and CVE-2025-20362 to get initial access to Cisco ASA firmware. They assess the backdoor can persist on ASA and Firepower Threat Defense systems, and CISA has updated Emergency Directive 25-03 after finding suspicious connections on a U.S. federal agency device.
The risk is no longer just vulnerable firmware. Infected appliances can keep serving as a foothold after updates, so patching removes exposure to the exploit but does not prove the device is clean.
CVSS 6.5 MEDIUM: update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA… EPSS 87% (100th percentile).
CISA federal remediation date Sep 26 · date passed
CVSS 9.9 CRITICAL: a vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco… EPSS 71% (99th percentile).
CISA federal remediation date Sep 26 · date passed