Connect with us

Cybersecurity

Cisco Patches Zero-Day RCE Exploited by China-Linked APT in Secure Email Gateways

Published

on

Cisco has released urgent security updates to address a critical vulnerability in its Secure Email Gateway and Secure Email and Web Manager products after confirming active exploitation by a China-linked threat group.

The flaw, tracked as CVE-2025-20393 and assigned the maximum CVSS score of 10.0, allows remote attackers to execute arbitrary commands with full root privileges. Cisco disclosed that the vulnerability had been abused as a zero-day in real-world attacks before a patch was available.

Details of the Vulnerability

The issue stems from improper validation of HTTP requests within the Spam Quarantine feature of Cisco AsyncOS Software. When exploited, the weakness enables unauthenticated attackers to remotely run system-level commands on affected appliances.

For an attack to succeed, three conditions must be present:

  • The device must be running a vulnerable version of Cisco AsyncOS
  • The Spam Quarantine feature must be enabled
  • The feature must be accessible from the internet

Active Exploitation by Advanced Threat Actor

Cisco previously revealed evidence that a China-aligned advanced persistent threat (APT) group, tracked as UAT-9686, began exploiting the vulnerability as early as late November 2025. According to Cisco’s findings, the attackers deployed multiple tools to maintain access and evade detection.

These included tunneling utilities such as ReverseSSH (also known as AquaTunnel) and Chisel, as well as a log-wiping tool called AquaPurge. The campaign also involved a lightweight Python-based backdoor, dubbed AquaShell, capable of receiving encoded instructions and executing them on compromised systems.

Patched Versions Released

Cisco confirmed that the latest updates not only close the vulnerability but also remove persistence mechanisms planted during the attacks. The following versions contain fixes:

Cisco Secure Email Gateway

  • AsyncOS 14.2 and earlier – fixed in 15.0.5-016
  • AsyncOS 15.0 – fixed in 15.0.5-016
  • AsyncOS 15.5 – fixed in 15.5.4-012
  • AsyncOS 16.0 – fixed in 16.0.4-016

Cisco Secure Email and Web Manager

  • AsyncOS 15.0 and earlier – fixed in 15.0.2-007
  • AsyncOS 15.5 – fixed in 15.5.4-007
  • AsyncOS 16.0 – fixed in 16.0.4-010

Security Recommendations for Customers

In addition to applying patches immediately, Cisco is urging customers to strengthen their security posture by:

  • Restricting appliance access behind firewalls
  • Preventing exposure to untrusted networks
  • Monitoring web logs for unusual inbound or outbound traffic
  • Disabling HTTP access to the main administrator interface
  • Turning off unnecessary network services
  • Enforcing strong authentication methods such as SAML or LDAP
  • Replacing default administrator passwords with strong, unique credentials

Why It Matters

Email gateways remain a high-value target for cyber espionage groups due to their access to sensitive communications. This incident highlights the growing trend of sophisticated threat actors rapidly weaponizing zero-day flaws in widely deployed enterprise infrastructure.

Organizations using Cisco Secure Email products are strongly advised to apply updates without delay and review their configurations to reduce external exposure.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO