Cisco finally fixed a top-level security issue that was allegedly being attacked by Chinese hackers.



  • Cisco Fixes Critical RCE Flaw (CVE-2025-20393) on Secure Email Devices
  • Chinese state-sponsored groups exploited it for weeks using Aquashell and tunneling tools.
  • Updates remove persistence mechanisms; Scope of global commitment unknown

A maximum severity vulnerability in certain Cisco products has finally been addressed after being allegedly exploited by Chinese hackers for several weeks.

In mid-December 2025, the networking giant disclosed a remote code execution (RCE) vulnerability in AsyncOS that affects Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) devices. It tracked the flaw as CVE-2025-20393 and gave it a severity score of 10/10 (critical).



Leave a Comment

Your email address will not be published. Required fields are marked *