Cisco Security Advisory
Follow
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerabilities
Multiple vulnerabilities exist in Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense Software. These issues could enable an authenticated, local attacker to run arbitrary commands with root privileges on the operating system. Exploitation requires the attacker to possess valid administrative credentials. The vulnerabilities stem from inadequate validation of user-supplied commands. An attacker could leverage these by logging into a device and inputting crafted data for specific commands. Successful exploitation grants the attacker the ability to execute commands as the root user. Cisco has issued software updates to resolve these vulnerabilities. Unfortunately, no workarounds are available to mitigate these security risks. The advisory detailing these issues is publicly accessible. These vulnerabilities are part of Cisco's August 2025 security advisory bundle.