CVE-2025-20393General(cisco / asyncos)

LOWCVSS 10.0 · CRITICALCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-12-24. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • asyncos
  • secure_email_and_web_manager_m170
  • secure_email_and_web_manager_m190
  • secure_email_and_web_manager_m195

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-05); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
asyncossecure_email_and_web_manager_m170secure_email_and_web_manager_m190secure_email_and_web_manager_m195secure_email_and_web_manager_m380secure_email_and_web_manager_m390secure_email_and_web_manager_m390xsecure_email_and_web_manager_m395secure_email_and_web_manager_m680secure_email_and_web_manager_m690

1 version affected across 21 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-05: 2Mentions · 2026-07-08: 1Mentions · 2026-10-05: 1Technical Details · 2026-02-05: 102-0507-0810-05
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-052
Disclosure1General1
2026-07-081
General1
Full discourse4 posts
  • starlabs@starlabs_sg
    General

    Ever wondered what happens when you pickle a mailbox? 🥒📬 (No, it’s not a recipe, it’s a vulnerability.) Our team breaks down CVE-2025-20393 in a new deep dive post covering root cause, internals & exploitation details https://starlabs.sg/blog/2026/01-pickling-the-mailbox-a-deep-dive-into-cve-2025-20393/ Written by @CurseRed & @bestswngs

    Post summary

    The post announces a forthcoming deep‑dive blog post on CVE‑2025‑20393, but the provided text does not contain any PoC, exploit code, patch information, technical details, or evidence of active exploitation.

    127186397.2K
    9.4K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『a single-byte integer overflow in the EUQ RPC protocol that bypasses authentication and chains into Python pickle deserialization — achieving unauthenticated remote code execution with a single HTTP request.』🧐 A Deep Dive into CVE-2025-20393 https://starlabs.sg/blog/2026/01-pickling-the-mailbox-a-deep-dive-into-cve-2025-20393/

    Post summary

    The text discloses a single‑byte integer overflow in the EUQ RPC protocol that bypasses authentication and enables unauthenticated remote code execution via a single HTTP request, providing detailed technical information.

    00002393
    6.7K followersView on X
  • Ask The Nerve@AskTheNerve

    Critical Cisco AsyncOS Zero-Day Actively Exploited (Network Security) A maximum-severity (CVSS 10.0) zero-day in Cisco AsyncOS (CVE-2025-20393) affecting Secure Email Gateway and Secure Email and Web Manager appliances is under active exploitation by a China-nexus APT (UAT-9686). The flaw allows unauthenticated remote code execution with root privileges when the Spam Quarantine feature is internet-exposed. Attackers deployed custom backdoors (AquaShell, AquaTunnel, etc.). Patches are now available; organizations are urged to update immediately.

    0000071
    19 followersView on X
  • CompuChris@compuchris
    General

    Cisco CVE-2025-20393: Critical Vulnerability | Kroll Threat Intelligence - Kroll #CISO https://news.google.com/rss/articles/CBMisAFBVV95cUxPdVQ5UWdoZmRaN3B6TVBkUi1aMlkwZERMWnhMajhrcVRtbW91T0ZqQVdmdW9yYnRYU05BNGlSYXRtVjEzeTlHczBQd1JyZkhLdjVWTjdlSWFobjFoWGVra0tEUzBrb251LWZsQjd1ZVJaN2hCbkt6VEdadDVTd1NRZ1lBZDJPeGlOblpMczFLR2VPalZLTFdJVUpOYTM1dUMwaWZQSFZvTTBEd1ZSU2g4Ug?oc=5

    Post summary

    A link to an article announcing Cisco CVE-2025-20393 as a critical vulnerability, but no further details are provided.

    0000041
    1.7K followersView on X
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
OSciscoasyncos---
HWciscosecure_email_and_web_manager_m170---
HWciscosecure_email_and_web_manager_m190---
HWciscosecure_email_and_web_manager_m195---
HWciscosecure_email_and_web_manager_m380---
HWciscosecure_email_and_web_manager_m390---
HWciscosecure_email_and_web_manager_m390x---
HWciscosecure_email_and_web_manager_m395---
HWciscosecure_email_and_web_manager_m680---
HWciscosecure_email_and_web_manager_m690---
HWciscosecure_email_and_web_manager_m690x---
HWciscosecure_email_and_web_manager_m695---
Appciscosecure_email_and_web_manager_virtual_appliance_m100v---
Appciscosecure_email_and_web_manager_virtual_appliance_m300v---
Appciscosecure_email_and_web_manager_virtual_appliance_m600v---
HWciscosecure_email_gateway_c195---
HWciscosecure_email_gateway_c395---
HWciscosecure_email_gateway_c695---
Appciscosecure_email_gateway_virtual_appliance_c100v---
Appciscosecure_email_gateway_virtual_appliance_c300v---
Appciscosecure_email_gateway_virtual_appliance_c600v---

Explore more