CISA: FIRESTARTER Backdoor Survives Cisco Patches

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CISA and the UK's NCSC said the FIRESTARTER backdoor targeted Cisco ASA/Firepower devices by exploiting two now-patched flaws — CVE-2025-20333 (CVSS 9.9) and CVE-2025-20362 (CVSS 6.5) — granting root code execution and unauthorized access to restricted URL endpoints.
- FIRESTARTER lodges itself in the device's boot sequence by manipulating the startup mount list, surviving firmware updates and reboots; CISA said only a hard power cycle (pulling the power cord) removes the implant, and Cisco recommended reimaging to fully clear persistence.
- Cisco tracks the activity cluster as UAT4356 (aka Storm-1849) and linked it to the 2024 ArcaneDoor campaign, while CISA noted FIRESTARTER shares overlap with a previously documented bootkit called RayInitiator and operates by hooking Cisco's LINA network processing engine.
- LINE VIPER, a post-exploitation toolkit deployed alongside FIRESTARTER, can execute CLI commands, capture packets, bypass VPN AAA authentication, suppress syslog messages, and force delayed reboots on compromised devices.
- A parallel joint US-UK advisory warned that China-nexus groups Volt Typhoon and Flax Typhoon are running botnets of compromised SOHO routers, security cameras, and IoT devices to mask espionage against critical infrastructure, with multiple groups sometimes sharing the same covert network.
- Check Point's Sergey Shykevich said the parallel use of shared covert networks reflects 'operational scale and maturity' that should concern any critical-infrastructure operator, arguing prevention must extend to overlooked connectivity infrastructure because attackers often dwell for weeks or months before detection.
Why it matters: FIRESTARTER rewrites the remediation playbook: organizations that applied Cisco's September patches on the assumption that updates cleared the threat are still exposed, and Cisco explicitly warns all device configuration should now be considered untrusted. The companion joint advisory shows the same perimeter-device targeting pattern is now being industrialized across China-nexus actors, with shared SOHO-router botnets making attribution and blocking harder for defenders of critical-infrastructure and government networks.
Ask SkimNews




