logo

CVE-2025-20393 Exploitation: A Maximum-Severity Zero-Day Vulnerability in Cisco AsyncOS Software Abused in Attacks by the China-Backed APT UAT-9686 

ID: 050e1874-e69f-58e6-813b-7f9ccad1751d

STIX ID: report--050e1874-e69f-58e6-813b-7f9ccad1751d

Feed Name: SOC Prime Blog

Threat Score
90/100

Date Published: 2025-12-18

Date Updated: 2026-04-30

Author: Veronika Telychko

...
...

The report details an active, high-severity zero-day (CVE-2025-20393, CVSS 10.0) in Cisco AsyncOS being exploited in the wild by a China-linked APT tracked as UAT-9686 to gain root command execution and persistence on affected Secure Email Gateway and Secure Email and Web Manager appliances; attackers have deployed tunneling tools (AquaTunnel/Chisel), a log-cleaning utility (AquaPurge), and a Python backdoor (AquaShell). Cisco and CISA have issued guidance and KEV listing, and vendors recommend isolating or rebuilding exposed appliances and applying mitigations until a patch is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.