Cisco has finally fixed a maximum-level security issue that was allegedly targeted by Chinese hackers.


  • Cisco Fixes Critical RCE Vulnerability (CVE-2025-20393) in Secure Email Appliances
  • Chinese state-sponsored groups exploited it for weeks using Aquashell and tunneling tools.
  • Updates remove persistence mechanisms; the extent of the global compromise remains unknown

A maximum severity vulnerability in some Cisco products has finally been patched after being allegedly exploited by Chinese hackers for several weeks.

In mid-December 2025, the networking giant disclosed a remote code execution (RCE) vulnerability in AsyncOS that affects Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) devices. He tracked the flaw as CVE-2025-20393 and gave it a severity score of 10/10 (critical).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top