HomeSecurityWarning! Critical zero-day vulnerability in Cisco AsyncOS

Warning! Critical zero-day vulnerability in Cisco AsyncOS

Cisco has warned users about a critical zero-day vulnerability in its Cisco AsyncOS software , which has been actively exploited by a Chinese threat group called UAT-9686 . The attacks target the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager .

Cisco

The network equipment company said it was notified of the campaign on December 10, 2025, and has identified a “limited subset of devices” with certain ports open to the internet. It is not known at this time how many customers have been affected.

“This attack allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected device,” said in an advisory. “Ongoing research has uncovered a persistence that has been ‘planted’ by threat actors to maintain a degree of control over compromised devices.”

See also: CISA: ASUS Live Update Vulnerability in KEV Catalog

Cisco AsyncOS: Vulnerability CVE-2025-20393

The unpatched vulnerability is tracked as CVE-2025-20393 and carries a CVSS score of 10.0. It involves an “improper input validation” case that allows threat actors to execute malicious instructions with elevated privileges on the underlying operating system.

All versions of Cisco AsyncOS software are affected. However, for a successful exploit to occur, the following conditions must be met for both physical and virtual versions of Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances:

– The device is configured with Spam Quarantine mode

– Spam Quarantine function is exposed and accessible from the internet

Warning! Critical zero-day vulnerability in Cisco AsyncOS

It's worth noting that Spam Quarantine is not enabled by default. To check if it is enabled, follow these steps:

1. Log in to the web management interface

2. Go to Network > IP Interfaces > [Select the interface on which Spam Quarantine is configured] (for Secure Email Gateway) or Management Appliance > Network > IP Interfaces > [Select the interface on which Spam Quarantine is configured] (for Secure Email and Web Manager)

3. If the Spam Quarantine option is selected, the feature is enabled

See also: JumpCloud Remote Assist: Vulnerability allows privilege escalation

Vulnerability Exploitation

Exploit activity observed by Cisco dates back to at least late November 2025, with UAT-9686 using the vulnerability to install tunneling tools such as ReverseSSH (also known as AquaTunnel) and Chisel, as well as a log cleaning utility called AquaPurge. The use of AquaTunnel has previously been associated with Chinese hacking groups such as APT41 and UNC5174.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Also deployed in the attacks is a lightweight Python backdoor called AquaShell, which is capable of receiving encoded commands and executing them. “It passively listens for unauthenticated HTTP POST requests containing specially crafted data,” Cisco said. “If such a request is detected, the backdoor will attempt to parse the contents using a custom decryption routine and execute them in the system shell.”

Warning! Critical zero-day vulnerability in Cisco AsyncOS

Protection

In the absence of a fix, users are urged to restore their devices to a secure configuration, restrict access from the internet, secure the devices behind a firewall to only allow traffic from trusted hosts, separate mail and management functionality into separate network interfaces, monitor web log traffic , and disable HTTP for the main admin portal.

See also: React2Shell vulnerability used to install Linux Backdoors

It is also recommended that they disable any network services that are not required, use strong end-user authentication methods such as SAML or LDAP, and change the default administrator password.

“In the event of a confirmed breach, device refactoring is, at this time, the only viable option to eliminate the persistence mechanism threat agent’s,” the company said.

This development has led the U.S. Cybersecurity and Infrastructure Security Administration (CISA) to add CVE-2025-20393 to the list of Known Exploitable Vulnerabilities (KEV), requiring Federal FCEB Agencies to implement the necessary mitigations.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS