Vulnerabilities & Exploits · APT / Espionage

Cisco Firewall Backdoors Survive Patching

Cisco ASA and FTD devices can stay compromised after the patch lands. The standard response — fix the CVEs and move on — misses that FIRESTARTER can remain active and let attackers come back without re-exploiting the original flaw.

CISA and the UK NCSC say FIRESTARTER is tied to a widespread campaign that used CVE-2025-20333 and CVE-2025-20362 to get initial access to Cisco ASA firmware. They assess the backdoor can persist on ASA and Firepower Threat Defense systems, and CISA has updated Emergency Directive 25-03 after finding suspicious connections on a U.S. federal agency device.

The risk is no longer just vulnerable firmware. Infected appliances can keep serving as a foothold after updates, so patching removes exposure to the exploit but does not prove the device is clean.

15 sources · Apr 27

CVE-2025-20362

NVD KEV

Known exploited · CISA KEV

CVSS 6.5 MEDIUM: update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA… EPSS 87% (100th percentile).

CISA federal remediation date Sep 26 · date passed

CVE-2025-20333

NVD KEV

Known exploited · CISA KEV

CVSS 9.9 CRITICAL: a vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco… EPSS 71% (99th percentile).

CISA federal remediation date Sep 26 · date passed

Timeline

Sources

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-04-28

Every edition of this story: Cisco Firewall Backdoors Survive Patching

More from today