CVE-2025-20393
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
Description
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Weakness: CWE-20
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Secure Email Gateway | Email Security | cna-assigner |
Vendor-reported products (2)
- Cisco · Cisco Secure Email
- Cisco · Cisco Secure Email and Web Manager
Vendor advisory
Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
Cisco’s rating: Critical (advisory CVSS 10.0) · Published Dec 17, 2025 · updated Jan 15, 2026 (revision 2.0)
Bug IDs: CSCws36549 , CSCws52505
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from