Junglewise Threat Intelligence

CVE-2025-20393: Cisco Secure Email Gateway command injection in Spam Quarantine

CVE-2025-20393 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2025-12-17

Executive brief

Cisco email and web security appliances are affected by a critical vulnerability that allows unauthorized individuals to take full control of the device. These appliances are used to filter malicious emails and manage web traffic for corporate networks. An attacker could exploit this to disrupt communications, steal sensitive data, or use the device as a foothold to attack other parts of the internal network.

Technical details

An improper input validation vulnerability exists in the Spam Quarantine feature of Cisco AsyncOS Software. The flaw is triggered by insufficient validation of incoming HTTP requests, allowing a remote, unauthenticated attacker to inject and execute arbitrary system commands. By sending a specially crafted HTTP request to the affected device, an attacker can gain full root-level access to the underlying operating system. This vulnerability has been observed being exploited in the wild. Cisco has released software updates to address this issue across affected AsyncOS versions.

Affected products

  • Cisco Secure Email Gateway AsyncOS < 15.0.5-016, 15.5.x < 15.5.4-012, 16.0.x < 16.0.4-016
  • Cisco Secure Email and Web Manager AsyncOS < 15.0.5-016, 15.5.x < 15.5.4-012, 16.0.x < 16.0.4-016

Timeline

  • 2025-12-17: advisory: Initial Cisco advisory and NVD publication
  • 2025-12-17: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-12-17: exploited: Confirmed active exploitation in the wild

Related threats