U.S. CISA adds Cisco, SonicWall, and ASUS flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20393 | Improper Input Validation in Cisco Secure Email and Web Appliances Allows Root Commands CVE-2025-20393 is an improper input validation flaw (CWE-20) in Cisco Secure Email Gateway, Secure Email, AsyncOS software, and Web Manager appliances that lets attackers execute arbitrary commands with root privileges on the underlying operating system. The flaw is triggered when an affected appliance processes improperly validated input, though the CISA record does not specify the access vector or whether authentication is required. Successful exploitation yields full compromise of the appliance at the highest OS privilege level, which is significant because these devices sit in the email- and web-security path of enterprise networks. Organizations running these Cisco appliances are affected; CVSS has not yet been published and no public proof-of-concept is known. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2025-12-17, EPSS estimates a 29.9% chance of exploitation within 30 days (98th percentile), and ransomware use remains undetermined. Do: Apply the mitigations or updates Cisco specifies in its advisory for CVE-2025-20393 without waiting for a CVSS score; the CISA KEV entry directs users to vendor mitigations, applicable BOD 22-01 cloud-service guidance, or discontinuing use if mitigations are unavailable. Because this record contains no fixed-release details, check the Cisco PSIRT advisory for the exact patched AsyncOS and Web Manager versions before planning the upgrade. In the meantime, review appliance logs and configurations for signs of unexpected command execution or changes, since active exploitation is confirmed and ransomware use is still unknown. | 10.0 | 30% | KEV |
| largeroughly tens of thousands of appliance deployments worldwide (exact installed base unpublished) | |
| CVE-2025-23006 | Unauthenticated Deserialization RCE in SonicWall SMA1000 Appliances CVE-2025-23006 is a deserialization of untrusted data flaw (CWE-502) in the Appliance Management Console (AMC) and Central Management Console (CMC) of SonicWall SMA1000 secure-access appliances. A remote, unauthenticated attacker who can reach a vulnerable console can submit crafted serialized data that, when processed, executes arbitrary operating-system commands on the appliance. Successful exploitation yields OS-level command execution, which is enough to fully compromise the appliance, pivot into the networks it protects, or stage ransomware. Any organization running a SonicWall SMA1000 appliance whose AMC or CMC is reachable — including management consoles exposed to the internet or to shared management networks — is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-24 with known ransomware use, and EPSS assigns a 23.4% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known and a CVSS score has not yet been published. Do: Apply SonicWall's fix or vendor-specified mitigations immediately, per CISA's KEV required action; the available data does not state fixed version numbers, so use SonicWall's advisory to identify the correct firmware. Until patched, restrict AMC/CMC access to trusted management networks and remove any direct internet exposure of the consoles. Because ransomware use is known, hunt for indicators of compromise on internet-reachable SMA1000 appliances, including unexpected processes, new accounts, and unusual outbound connections. | 9.8 | 23% | KEV ransomware |
| largeon the order of tens of thousands of SMA1000-series appliance deployments, with likely thousands of management consoles internet-exposed | |
| CVE-2025-40602 | Missing Authorization Flaw in SonicWall SMA1000 Appliance Management Console CVE-2025-40602 is a missing-authorization vulnerability (CWE-862, with CWE-250 unnecessary-privilege issues) in the appliance management console (AMC) of SonicWall's SMA1000 secure-access appliances, characterized by CISA as a privilege escalation flaw; the CVSS vector (AV:N/AC:H/PR:H/UI:N, CVSS 3.1 score 6.6) indicates it is reachable over the network but requires an attacker that already holds high privileges. An attacker who has obtained AMC access can invoke insufficiently authorized actions to escalate privileges and gain high-impact control of the appliance, with high confidentiality, integrity, and availability impact. Affected products are the SMA1000 appliance line — SMA 6200, 6210, 7200, and 7210 firmware and the SMA 8200V virtual appliance. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-17 and SonicWall has warned of active exploitation and shipped fixes, while EPSS estimates a 2.1% probability of exploitation within 30 days (81st percentile) and ransomware use is unknown. Do: Apply the patched SMA1000 firmware identified in SonicWall's security advisory immediately (the source data does not specify the fixed version), and follow CISA BOD 22-01 guidance for cloud services or discontinue use if mitigations are unavailable. Until patched, restrict AMC access to trusted management networks or a VPN, and review appliance logs for indicators of unauthorized access since exploitation is confirmed in the wild. | 6.6 | 2% | KEV |
| large≈10,000–100,000 SMA1000 appliances/management consoles deployed (exact internet-exposed count unknown) | |
| CVE-2025-59374 | Supply Chain-Embedded Malicious Code in ASUS Live Update Utility Certain builds of the ASUS Live Update automatic-update client were distributed containing unauthorized code planted through a supply chain compromise (CWE-506, embedded malicious code). The embedded code only caused devices to perform unintended actions when the device met specific attacker-defined targeting conditions and had installed one of the compromised versions, so most installations of the utility were not visibly affected. Where the targeting conditions were met, the malicious code ran with no user privileges required and carried high impact to confidentiality, integrity and availability (CVSS 4.0 score 9.3, critical). The Live Update client reached End-of-Support in October 2021, and ASUS states that no currently supported devices or products are affected, so exposure is limited to legacy systems that installed the compromised builds. CISA added the issue to the Known Exploited Vulnerabilities catalog on 2025-12-17 after evidence of active exploitation; no public proof-of-concept is known and EPSS estimates a 1.2% probability of exploitation in the next 30 days (66th percentile). Do: Because Live Update is end-of-support, no patched release exists: inventory legacy ASUS systems that currently or previously ran the client, determine whether compromised builds were installed, and remove or discontinue the utility per the CISA KEV required action (apply vendor mitigations or discontinue use, with BOD 22-01 applying to federal agencies). Check ASUS security advisories for indicators of the compromised versions and hunt on legacy ASUS endpoints for unexpected outbound connections or other signs of the 'unintended actions' described. Supported ASUS products are not affected, so no action is needed on current, in-support devices. | 9.3 | 1% | KEV |
| massmillions of ASUS consumer PCs carried the preinstalled Live Update client, though only a small, targeted subset that installed the compromised builds and met… |
Full article603 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 18, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, SonicWall, and ASUS flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple and Gladinet CentreStack and Triofox flaws to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the flaws added to the catalog:
- CVE-2025-20393 (CVSS score of 10.0) Cisco Multiple Products Improper Input Validation Vulnerability
- CVE-2025-40602 (CVSS score of 6.6) SonicWall SMA1000 Missing Authorization Vulnerability
- CVE-2025-59374 (CVSS score of 9.3) ASUS Live Update Embedded Malicious Code Vulnerability
Cisco reported a December 10 campaign targeting certain Secure Email Gateway appliances with exposed ports, enabling attackers to run root-level commands and plant persistence mechanisms. Threat actors exploited a Remote Command Execution Vulnerability, tracked as CVE-2025-20393, in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.
“On December 10, Cisco became aware of a new cyberattack campaign targeting a limited subset of appliances with certain ports open to the internet that are running Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.” reads the advisory. “This attack allows the threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. The ongoing investigation has revealed evidence of a persistence mechanism planted by the threat actors to maintain a degree of control over compromised appliances.”
The second vulnerability added to the catalog, tracked as CVE-2025-40602, is a local privilege escalation issue, which is due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). This week, SonicWall urged customers to address this vulnerability that was exploited as a zero-day in attacks in the wild.
“A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).” reads the advisory published by the company. “Please note that SonicWall Firewall products are not affected by this vulnerability.”
The vendor warned customers that the vulnerability was chained with CVE-2025-23006 in zero-day attacks to escalate privileges. Sonicwall has not disclosed details about the attacks that exploited the flaw as a zero-day, nor the attackers’ motivations.
“This vulnerability was reported to be leveraged in combination with CVE-2025-23006 (CVSS score 9.8) to achieve unauthenticated remote code execution with root privileges. CVE-2025-23006 was remediated in build version 12.4.3-02854 (platform-hotfix) and higher versions (released on Jan 22, 2025).” continues the advisory. “SonicWall PSIRT strongly advises users of the SMA1000 product to upgrade to the latest hotfix release version to address the vulnerability.”
CISA also added a critical ASUS Live Update flaw (CVE-2025-59374) to its KEV catalog after confirming active exploitation. The issue stems from a supply chain compromise in which certain Live Update versions were distributed with embedded malicious code, enabling unintended actions on specifically targeted devices. The vulnerability traces back to the ShadowHammer campaign uncovered in 2019, when threat actors trojanized ASUS updates to target a small set of users identified by MAC addresses. ASUS fixed the issue in 2019, but Live Update reached end of support in December 2025.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the CISCO and SonicWall vulnerabilities by December 24, 2025, and Asus flaw by January 7, 2025
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185830/security/u-s-cisa-adds-cisco-sonicwall-and-asus-flaws-to-its-known-exploited-vulnerabilities-catalog.html