
Safe Python scanner for Cisco CVE-2025-20333 (Cisco ASA/FTD WebVPN Buffer Overflow)
A Python-based diagnostic scanner for Cisco ASA / FTD VPN Web Server Buffer Overflow (CVE-2025-20333).
CVE-2025-20333 is a critical heap-based buffer overflow vulnerability in the WebVPN file upload handler that can lead to remote code execution (RCE) as root when successfully exploited.
This tool performs safe, non-destructive testing by checking whether vulnerable endpoints (primarily the file upload handler) are reachable. It is designed for security researchers, penetration testers, and system administrators to assess exposure on systems they are authorized to test.
Important: This script only performs GET requests and does not attempt exploitation.
python CVE-2025-20333-Scanner.py https://target-vpn.example.com