CVE-2026-20008
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability
Description
A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root. This vulnerability exists because user-provided input is not properly sanitized. An attacker could exploit this vulnerability by crafting valid Lua code and submitting it as a malicious parameter for a CLI command. A successful exploit could allow the attacker to inject Lua code, which could lead to arbitrary code execution as the root user. To exploit this vulnerability, an attacker must have valid Administrator credentials.
Weakness: CWE-78
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Adaptive Security Appliance (ASA) Check your version | Firewall / NGFW | cna-assigner |
| Cisco | Cisco Firepower Threat Defense (FTD) Check your version | Firewall / NGFW | cna-assigner |
Vendor-reported products (2)
- Cisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco · Cisco Secure Firewall Threat Defense (FTD) Software
Vendor advisory
cisco-sa-asaftd-luainject-VescqgmS
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability
Cisco’s rating: Medium (advisory CVSS 6.0) · Published Mar 4, 2026
Bug IDs: CSCwo73888 , CSCwo95496
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from