Cisco has finally fixed a maximum-level security issue that was reportedly targeted by Chinese hackers


  • Cisco fixes critical RCE flaw (CVE-2025-20393) in Secure Email appliances
  • Chinese state-sponsored groups exploited it for weeks using Aquashell and tunneling tools
  • Updates remove persistence mechanisms; the extent of global compromise remains unknown

A maximum severity vulnerability in certain Cisco products has finally been resolved after allegedly being exploited by Chinese hackers for several weeks.

In mid-December 2025, the networking giant disclosed a remote code execution (RCE) vulnerability in AsyncOS that affects Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances. It tracked the bug as CVE-2025-20393 and gave it a severity rating of 10/10 (Critical).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top