Cisco ASA and FTD devices can stay compromised after the patch lands. The standard response — fix the CVEs and move on — misses that FIRESTARTER can remain active and let attackers come back without re-exploiting the original flaw.
CISA and the UK NCSC say FIRESTARTER is tied to a widespread campaign that used CVE-2025-20333 and CVE-2025-20362 to get initial access to Cisco ASA firmware. They assess the backdoor can persist on ASA and Firepower Threat Defense systems, and CISA has updated Emergency Directive 25-03 after finding suspicious connections on a U.S. federal agency device.
The risk is no longer just vulnerable firmware. Infected appliances can keep serving as a foothold after updates, so patching removes exposure to the exploit but does not prove the device is clean.
CVSS 6.5 MEDIUM: update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA… EPSS 87% (100th percentile).
CISA federal remediation date Sep 26 · date passed
CVSS 9.9 CRITICAL: a vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco… EPSS 71% (99th percentile).
CISA federal remediation date Sep 26 · date passed
are warning about a custom malware called Firestarter persisting on Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software.
CISA said the unnamed department was infected with malware called “FIRESTARTER” that allowed the hackers to return to the Cisco device in March without re-exploiting the original vulnerabilities.