← Vulnerability feed

Vulnerability record · CVE-2025-20393 · published 17 December 2025

CVE-2025-20393: Cisco AsyncOS Spam Quarantine HTTP request validation flaw allows root command execution

Cisco · Asyncos

Cisco AsyncOS Software for Secure Email Gateway and Secure Email and Web Manager fails to properly validate HTTP requests in the Spam Quarantine feature. An unauthenticated remote attacker can send a crafted HTTP request to execute arbitrary commands as root on the underlying operating system. The flaw is rated CVSS 10.0 and is listed in CISA KEV, making it a top-priority exposure for internet-facing email security appliances.

10.0 CVSS 3.1 Critical CISA KEV since 17 Dec 2025 EPSS 32% · top 1.7% CWE-20 · Improper input validation
10.0CVSS 3.1 base score
32%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote root command execution with a CVSS 10.0 score and confirmed CISA KEV exploitation status makes this an urgent perimeter risk.

What it is

Cisco AsyncOS Software for Secure Email Gateway and Secure Email and Web Manager fails to properly validate HTTP requests in the Spam Quarantine feature. An unauthenticated remote attacker can send a crafted HTTP request to execute arbitrary commands as root on the underlying operating system. The flaw is rated CVSS 10.0 and is listed in CISA KEV, making it a top-priority exposure for internet-facing email security appliances.

Impact

An attacker gains arbitrary command execution with root privileges on the affected appliance, giving full control of the device and any data or credentials it handles. Because the device sits at the email perimeter, compromise can also expose mail flow and connected infrastructure.

Attack surface

Reachable over the network via HTTP requests to the Spam Quarantine feature; the CVSS vector shows no privileges required and no user interaction. Any internet-exposed management or quarantine interface on an affected appliance is a candidate entry point.

Exploitation

CVE-2025-20393 was added to CISA KEV on 2025-12-17 with a remediation due date of 2025-12-24, indicating known exploitation in the wild. EPSS gives a 30-day exploitation probability of roughly 29.9 percent (98th percentile); no ransomware campaign use is documented.

What to do

  • Apply the Cisco security advisory patch for AsyncOS on Secure Email Gateway and Secure Email and Web Manager immediately, ahead of the KEV due date.
  • If patching cannot be completed, restrict access to the Spam Quarantine and management interfaces to trusted networks or disable the feature per Cisco guidance.
  • Remove direct internet exposure of appliance management and quarantine interfaces; place them behind a VPN or access-controlled jump host.
  • Rotate credentials and inspect the appliance for unauthorized accounts, cron jobs, or configuration changes after any suspected exposure.
  • Monitor Cisco advisory updates and CISA KEV for revised mitigation instructions.

Detection

  • Review HTTP access and web server logs on AsyncOS appliances for anomalous or malformed requests to Spam Quarantine endpoints.
  • Hunt for unexpected root-level process execution, new files, or outbound connections originating from the email gateway.
  • Audit appliance configuration and account changes for signs of post-exploitation persistence.
  • Correlate network egress from email security appliances with threat intelligence for command-and-control activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-20393 to the Known Exploited Vulnerabilities catalog on 17 December 2025 as "Cisco Multiple Products Improper Input Validation Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 December 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-20393 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed8.8CVE-2022-20871Cisco asyncos os command injection vulnerabilityA vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance…EPSS 1.9%8.8CVE-2022-20868Cisco asyncos hard-coded credentials vulnerabilityA vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appl…EPSS 0.74%8.8CVE-2021-1359Cisco web security appliance vulnerabilityA vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker…EPSS 1.9%8.8CVE-2019-15956Cisco asyncos improper access control vulnerabilityA vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote…EPSS 0.98%8.6CVE-2019-1947Cisco email security appliance improper input validation vulnerabilityA vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthentica…EPSS 1.9%8.6CVE-2019-1886Cisco asyncos improper input validation vulnerabilityA vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a deni…EPSS 1.3%8.6CVE-2018-15460Cisco asyncos improper input validation vulnerabilityA vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthentic…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2025-20393), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.