ZeroHour
The Recordpublished ()ingested

Chinese attackers exploiting zero-day to target Cisco email security products

criticalExploit / PoCimportance 60CVE-2025-20393

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20393
Improper Input Validation in Cisco Secure Email and Web Appliances Allows Root Commands

CVE-2025-20393 is an improper input validation flaw (CWE-20) in Cisco Secure Email Gateway, Secure Email, AsyncOS software, and Web Manager appliances that lets attackers execute arbitrary commands with root privileges on the underlying operating system. The flaw is triggered when an affected appliance processes improperly validated input, though the CISA record does not specify the access vector or whether authentication is required. Successful exploitation yields full compromise of the appliance at the highest OS privilege level, which is significant because these devices sit in the email- and web-security path of enterprise networks. Organizations running these Cisco appliances are affected; CVSS has not yet been published and no public proof-of-concept is known. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2025-12-17, EPSS estimates a 29.9% chance of exploitation within 30 days (98th percentile), and ransomware use remains undetermined.

Do: Apply the mitigations or updates Cisco specifies in its advisory for CVE-2025-20393 without waiting for a CVSS score; the CISA KEV entry directs users to vendor mitigations, applicable BOD 22-01 cloud-service guidance, or discontinuing use if mitigations are unavailable. Because this record contains no fixed-release details, check the Cisco PSIRT advisory for the exact patched AsyncOS and Web Manager versions before planning the upgrade. In the meantime, review appliance logs and configurations for signs of unexpected command execution or changes, since active exploitation is confirmed and ransomware use is still unknown.

10.030% KEV
  • Cisco Secure Email Gateway / Secure Email
  • Cisco AsyncOS Software
  • Cisco Web Manager appliance
largeroughly tens of thousands of appliance deployments worldwide (exact installed base unpublished)
Full article558 words · extracted from therecord.media · click to collapse

Chinese hackers have been exploiting a vulnerability in a popular Cisco email management tool since late November, the company said Wednesday.

Cisco warned customers about the bug — CVE-2025-20393 — writing in an advisory that the vulnerability carries a maximum severity score of 10 and affects appliances with certain ports open to the internet that are running the company’s AsyncOS Software for its Secure Email Gateway and Secure Email and Web Manager.

Those products provide teams with a centralized interface to manage and report functions across multiple Cisco email devices, letting users manage policies, administer devices, enhance security and quarantine spam messages. 

The company said it became aware of the intrusion campaign on December 10 when it saw a “limited subset of appliances” being targeted. The hackers have used a variety of tools to maintain their access to compromised devices, according to an ongoing investigation by Cisco.

The company released a companion blog from its security arm that attributed the campaign to a Chinese threat group. It based the assessment on the tools and infrastructure used during attacks. 

The Cybersecurity and Infrastructure Security Agency confirmed that CVE-2025-20393 is being exploited and ordered all federal civilian agencies to apply mitigations for it by December 24.

Cisco said there is currently no patch for the bug but it provided a list of actions customers can take to protect themselves. 

The issue concerns a spam prevention feature that has to be manually enabled by customers. If the feature is exposed to and reachable from the internet, both physical and virtual instances of the Cisco Secure Email Gateway, as well as the Web Manager appliances, are at risk. 

Cisco provided a detailed process for how customers can restore devices that have been exposed to the internet to a secure configuration. If that is not possible, customers should contact Cisco to see if their appliance has been compromised. 

“In case of confirmed compromise, rebuilding the appliances is, currently, the only viable option to eradicate the threat actors’ persistence mechanism from the appliance,” Cisco explained. 

“In addition, Cisco strongly recommends restricting access to the appliance and implementing robust access control mechanisms to ensure that ports are not exposed to unsecured networks.”

The company added that its email and web manager appliances should be put behind devices like a firewall.  

Cisco attributed the attacks to a Chinese threat actor it called UAT-9686 and said the group used a persistence tool called AquaShell to maintain their access and take other actions. 

The company said the group has technical overlaps with UNC5174 and APT41, one of the most prolific Chinese state-affiliated cyber groups. Its members were charged by the U.S. in 2020 for breaching more than 100 entities worldwide. 

The FBI has issued arrest warrants for five Chinese nationals tied to the group, including Zhang Haoran and Tan Dailin, for alleged cyber intrusions spanning espionage, ransomware deployment, and software supply chain attacks.

The same group has also been linked to intrusions targeting Southeast Asian government agencies, as well as Taiwan.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/chinese-attackers-zero-day