Vulnerability record · CVE-2025-20393 · published 17 December 2025
CVE-2025-20393: Cisco AsyncOS Spam Quarantine HTTP request validation flaw allows root command execution
Cisco · Asyncos
Cisco AsyncOS Software for Secure Email Gateway and Secure Email and Web Manager fails to properly validate HTTP requests in the Spam Quarantine feature. An unauthenticated remote attacker can send a crafted HTTP request to execute arbitrary commands as root on the underlying operating system. The flaw is rated CVSS 10.0 and is listed in CISA KEV, making it a top-priority exposure for internet-facing email security appliances.
Description
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote root command execution with a CVSS 10.0 score and confirmed CISA KEV exploitation status makes this an urgent perimeter risk.
What it is
Cisco AsyncOS Software for Secure Email Gateway and Secure Email and Web Manager fails to properly validate HTTP requests in the Spam Quarantine feature. An unauthenticated remote attacker can send a crafted HTTP request to execute arbitrary commands as root on the underlying operating system. The flaw is rated CVSS 10.0 and is listed in CISA KEV, making it a top-priority exposure for internet-facing email security appliances.
Impact
An attacker gains arbitrary command execution with root privileges on the affected appliance, giving full control of the device and any data or credentials it handles. Because the device sits at the email perimeter, compromise can also expose mail flow and connected infrastructure.
Attack surface
Reachable over the network via HTTP requests to the Spam Quarantine feature; the CVSS vector shows no privileges required and no user interaction. Any internet-exposed management or quarantine interface on an affected appliance is a candidate entry point.
Exploitation
CVE-2025-20393 was added to CISA KEV on 2025-12-17 with a remediation due date of 2025-12-24, indicating known exploitation in the wild. EPSS gives a 30-day exploitation probability of roughly 29.9 percent (98th percentile); no ransomware campaign use is documented.
What to do
- Apply the Cisco security advisory patch for AsyncOS on Secure Email Gateway and Secure Email and Web Manager immediately, ahead of the KEV due date.
- If patching cannot be completed, restrict access to the Spam Quarantine and management interfaces to trusted networks or disable the feature per Cisco guidance.
- Remove direct internet exposure of appliance management and quarantine interfaces; place them behind a VPN or access-controlled jump host.
- Rotate credentials and inspect the appliance for unauthorized accounts, cron jobs, or configuration changes after any suspected exposure.
- Monitor Cisco advisory updates and CISA KEV for revised mitigation instructions.
Detection
- Review HTTP access and web server logs on AsyncOS appliances for anomalous or malformed requests to Spam Quarantine endpoints.
- Hunt for unexpected root-level process execution, new files, or outbound connections originating from the email gateway.
- Audit appliance configuration and account changes for signs of post-exploitation persistence.
- Correlate network egress from email security appliances with threat intelligence for command-and-control activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-20393 to the Known Exploited Vulnerabilities catalog on 17 December 2025 as "Cisco Multiple Products Improper Input Validation Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 December 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-20393 | US Government Resource |
Track CVE-2025-20393 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-20393), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.