ACEN MDR Threat Alert – Cisco Secure Firewall Management Center (CVE-2025-20265, CVSS 10.0)

On the 14th of August 2025, Cisco disclosed a critical vulnerability (CVE-2025-20265, CVSS 10.0) in its Secure Firewall Management Center (FMC) Software, specifically when RADIUS authentication is enabled.

The flaw allows unauthenticated remote attackers to inject and execute arbitrary shell commands with elevated privileges. No prior access is needed – making this an extremely serious risk for internet-exposed FMC systems.

What’s going on?

⚠️ This vulnerability resides in the RADIUS authentication subsystem of Cisco Secure FMC. It’s caused by improper input validation during the authentication process.

⚠️ Attackers can exploit the flaw by sending specially crafted credentials to a vulnerable FMC interface (web-based or SSH), leading to remote code execution with elevated privileges.

⚠️ Affected versions & mitigation:

ProductAffected VersionsMitigation
Cisco Secure FMC7.0.7 and 7.7.0 (with RADIUS enabled)Apply the latest patches from Cisco immediately

You can find Cisco’s official advisory here: Cisco Security Advisory – CVE-2025-20265

Why is this a problem?

The vulnerability enables:

  • Remote command execution without authentication
  • Privilege escalation on the FMC system
  • Lateral movement across the internal network
  • Data exfiltration and system compromise

There are no workarounds other than patching or disabling RADIUS authentication, making rapid response essential.

How does ACEN protect its customers?

If you’re using ACEN’s Extended Detection and Response (XDR) solution, it is designed to block many types of exploitation attempts that occur after the initial compromise. This enables our teams to stop threats and launch an investigation.

ACEN’s MDR service also deploys tailored detection scenarios that monitor system logs from Windows, firewalls, Microsoft 365, and other sources to identify and stop threat actors.

In the event of a serious incident, our Computer Security Incident Response Team (CSIRT) is available to provide expert support and guidance.

We continue to emphasize the importance of proactive security measures. Please ensure your systems are updated with the latest patches and configurations.

What can you do to mitigate the attack?

✅ Apply Cisco’s security updates immediately
✅ Disable RADIUS authentication on FMC if patching isn’t feasible right away
✅ Limit access to FMC interfaces through network segmentation and access controls

But what if you can’t?

🛡️ Isolate FMC systems from external access
🛡️ Temporarily disable RADIUS authentication until patched
🛡️ Monitor authentication logs for anomalies and brute-force attempts

Need help to mitigate the risks?

Get in contact with Ken Van Hasselt today!

Share this article

Interested in learning more about our solutions and how they can benefit your business?

Contact us now for personalized insights and solutions.

Related articles

ACEN - Featured Image Wordpress - Orlox Merger 1200 x 628

Orlox, Specialist in Microsoft security becomes part of ACEN.

Kontich, Belgium — [13/01/2026] — ACEN, the leading Belgian provider of tailored cybersecurity solutions,...

ACEN - Featured Image Cybersecurity - Wie is er verantwoordelijk als het echt misgaat - 1200 x 628 pixels

Cybersecurity – Who is responsible when things really go wrong?

What if your company were hit by a cyberattack tomorrow? What if… production came...

ACEN - Featured Image Wordpress - 1200 x 628 pixels

The golden rules of a secure Out-Of-Office message

Let’s face it… We all love setting an out-of-office message as it means we’re...

Subscribe to our newsletter

We only use your e-mail address to send newsletters.

We do not pass on your address to third parties.

Security as a Service

Experience peace of mind with our Security as a Service – your company’s ultimate shield against threats, featuring reliable 24/7 protection, local support, and a tailored approach to meet all your unique security needs.

We are looking for talent

Check out our careers platform and discover our wide range of cybersecurity opportunities!

ACEN logo with orange swirl
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.