Cisco Patches Critical Zero-Day RCE Vulnerability Exploited by China-Linked APT
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Cisco recently addressed a critical security flaw in its AsyncOS Software for Secure Email Gateway and Secure Email and Web Manager, identified as CVE-2025-20393. This vulnerability, which has a maximum severity score of 10.0, allows remote command execution due to insufficient validation of HTTP requests by the Spam Quarantine feature. Cisco disclosed that the flaw was actively exploited by the China-linked APT group UAT-9686, with evidence of exploitation dating back to late November 2025.
Successful exploitation of this vulnerability requires that the appliance is running a vulnerable version of Cisco AsyncOS Software, has the Spam Quarantine feature enabled, and is accessible from the internet. The attackers utilized this flaw to deploy tunneling tools like ReverseSSH and Chisel, as well as a log cleaning utility called AquaPurge, along with a lightweight Python backdoor named AquaShell.
Cisco has released patches for the affected AsyncOS Software versions, including fixes for Cisco Email Security Gateway and Secure Email and Web Manager. The specific versions that have been addressed include Cisco AsyncOS Software Release 14.2 and earlier, 15.0, 15.5, and 16.0 for the Email Security Gateway, and similar versions for the Secure Email and Web Manager.
Implications for Organizations
This incident underscores the importance of timely software updates and the need for organizations to monitor their systems for vulnerabilities. The exploitation of such a critical flaw by a sophisticated APT group highlights the evolving threat landscape and the potential for severe impacts on organizations that do not maintain robust security practices.
Organizations using Cisco products should ensure they are running the latest software versions and follow Cisco’s hardening guidelines. These include securing appliances behind a firewall, monitoring web log traffic for anomalies, and enforcing strong authentication methods.
As cyber threats continue to grow in complexity, organizations must remain vigilant and proactive in their cybersecurity strategies to mitigate risks associated with vulnerabilities like CVE-2025-20393.
Key Takeaways
- Update Cisco AsyncOS Software to the latest versions to mitigate the vulnerability.
- Secure appliances behind a firewall to limit exposure to the internet.
- Monitor web log traffic for any unexpected activity related to your email gateways.
- Disable HTTP access for the main administrator portal to enhance security.
- Implement strong authentication methods, such as SAML or LDAP, for accessing appliances.
Key Terms & Concepts
- CVE-2025-20393: In this article, CVE-2025-20393 refers to a critical remote command execution vulnerability in Cisco AsyncOS Software.
- APT: APT stands for Advanced Persistent Threat, which refers to a prolonged and targeted cyberattack often orchestrated by skilled threat actors.
- Cisco AsyncOS Software: Cisco AsyncOS Software is the operating system used in Cisco’s Secure Email Gateway and Secure Email and Web Manager products.
- ReverseSSH: ReverseSSH is a tunneling tool that allows remote access to a device behind a firewall or NAT.
- AquaShell: AquaShell is a lightweight Python backdoor used by attackers to execute commands on compromised systems.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.