Cisco logo
– Ben Wodecki/SDxCentral

The Cybersecurity and Infrastructure Security Agency (CISA) issued a high alert on malware affecting Cisco firewall products.

In its advisory, CISA flagged a malware known as Firestarter. The threat is being used against Cisco Firepower and Secure Firewall products running Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software.

The Firestarter tool targets vulnerabilities CVE-2025-20333 and CVE-2025-20362, which were disclosed in September as affecting ASA and FTD solutions. Breaches of the VPN web server software, including flaws that allow an authenticated remote attacker to execute arbitrary code on a compromised device, were serious enough to warrant an emergency CISA directive. Statistics from that period estimated that almost 50,000 Cisco firewall devices were at risk from the vulnerabilities, with the attack linked to supposed China-nexus threat ArcaneDoor, prompting pressure on Cisco from the U.S. government.

With the Firestarter malware, attackers can maintain access to affected Cisco devices even after security updates. CISA advised agencies to immediately disconnect compromised devices from the network while remaining powered on, before submitting an official report to the body for incident response and eviction.

For devices with no detected compromise, organizations must apply all critical software updates and specific persistence patches and perform a physical hard reset on Firepower and Secure Firewall units by April 30. They are also advised to decommission any legacy ASA hardware and update all remaining devices within 48 hours of any new Cisco software release.

The new threat remains associated with the ArcaneDoor campaign, which Cisco’s Talos research unit linked to threat actor UAT-4356, classified by Microsoft as a China-nexus threat under the name of Storm-1849.

CISA last week joined the NSA and FBI to warn of “China-nexus cyber actors” using networks made up of compromised routers, IoT devices, and smart appliances. The advisory flagged recent efforts by reported Chinese state-sponsored groups such as Volt Typhoon, which launched a botnet attack that mainly involved end-of-life Cisco and NetGear routers.