NG Solution Team
Technology

Is Cisco facing a cyber attack exploiting a zero-day vulnerability?

Networking giant Cisco has uncovered a cyber attack potentially linked to Chinese threat actors exploiting a zero-day flaw in its software. This vulnerability, found in Cisco AsyncOS, enables attackers to execute commands with root privileges on affected systems. The attack targets the secure email gateway and web manager, with a focus on appliances featuring “Spam Quarantine” enabled.

The company identified the intrusion attempts on December 10 and has since isolated a limited number of affected devices. Cisco has not disclosed the number of impacted customers but is actively investigating the issue and working on a permanent fix. Currently, the only solution for compromised systems is a complete software rebuild to remove the persistent threat.

The vulnerability, tracked as CVE-2025-20393, involves improper input validation, allowing malicious instructions to be executed with elevated privileges. Cisco notes that a successful hack requires specific conditions, particularly around the Spam Quarantine feature.

The campaign, linked to Chinese hacking groups, has been ongoing since at least late November 2025. As part of the attack, a lightweight Python backdoor named AquaShell was deployed, capable of executing encoded commands received via unauthenticated HTTP POST requests.

Related posts

Has Nevoya achieved cost parity with diesel for its EV truck fleet?

Jessica Williams

What will the American Data Centers & AI Conference offer?

Jessica Williams

Has Repsense secured €2 million in seed funding?

Emily Brown

Leave a Comment

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy