Cisco Firewall Backdoors Survive Patching

Cisco ASA and FTD devices can stay compromised after the patch lands. The standard response — fix the CVEs and move on — misses that FIRESTARTER can remain active and let attackers come back without re-exploiting the original flaw. CISA and the UK NCSC say FIRESTARTER is tied to a widespread campaign that used CVE-2025-20333 and CVE-2025-20362 to get initial access to Cisco ASA firmware. They assess the backdoor can persist on ASA and Firepower Threat Defense systems, and CISA has updated Emergency Directive 25-03 after finding suspicious connections on a U.S. federal agency device. The risk is no longer just vulnerable firmware. Infected appliances can keep serving as a foothold after updates, so patching removes exposure to the exploit but does not prove the device is clean.

Part of the PlainSec briefing for 2026-04-28

Sources