# CVE-2025-20393 — Cisco Secure Email Gateway RPC Integer Overflow Enabling Auth Bypass and Unsafe Pickle Deserialization (CVSS 10.0), Exploited by China-Nexus APT UAT-9686

> A single-byte integer overflow in the EUQ RPC message header of Cisco AsyncOS Software (Secure Email Gateway / Secure Email and Web Manager) lets an unauthenticated remote attacker bypass serial-number authentication and trigger unsafe cPickle deserialization for arbitrary command execution as root. Cisco confirmed active exploitation since late November 2025 by China-nexus actor UAT-9686, which deployed the AquaShell Python backdoor, AquaTunnel (ReverseSSH-derived) and Chisel tunnels, and the AquaPurge log-cleaning utility.

- **Published:** 2026-02-05T00:00:00Z
- **Last reviewed:** 2026-02-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1541
- **ID:** TL-2026-1541
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** UAT-9686 (China)
- **Detections:** 9 · **IOCs:** 17 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-20393

## Description

CVE-2025-20393 affects the Spam Quarantine / End User Quarantine (EUQ) RPC service (TCP port 83, quarantine web UI commonly on port 6025) shipped in Cisco AsyncOS Software for Secure Email Gateway (formerly Email Security Appliance) and Secure Email and Web Manager (formerly Content Security Management Appliance). The EUQ RPC wire format uses the struct layout '>BBIIBB32s' (version, ttl, msg_len, msg_type, src_len, dst_len, txn_tag), where src_len and dst_len are single-byte unsigned-char fields (0-255). Because the service runs under Python 2.6 (EOL since 2013), struct.pack('>B', n) silently truncates n modulo 256 instead of raising struct.error as modern Python does. An attacker can therefore craft a payload whose true length is 256 or 289 bytes so that the encoded destination-length byte wraps to 0 (or to a value matching the appliance's known serial number). When the receiver's read_message() function evaluates 'if destination_length:', a wrapped-to-zero length causes destination to be set to an empty string, which bypasses the check that normally validates the message's destination against the appliance's serial number. The now-unauthenticated message body is then passed directly to cPickle.loads(), Python's insecure object deserializer, allowing an attacker-supplied pickle object with a __reduce__ gadget to execute arbitrary OS commands with root privileges via a single crafted HTTP request — no credentials, no user interaction. Cisco's advisory (cisco-sa-sma-attack-N9bf4, published 2025-12-17, updated 2026-01-15) describes the flaw generically as 'Insufficient validation of HTTP requests by the Spam Quarantine feature'; STAR Labs' 2026-02-05 patch-diffing research against AsyncOS 15.5.4 (which adds explicit destination-length validation) reverse-engineered the true integer-overflow/pickle root cause and published a working proof-of-concept demonstrating both the serial-matching and universal zero-length bypass techniques. Cisco Talos separately confirmed exploitation in the wild dating to at least late November 2025 by a Chinese-nexus actor tracked as UAT-9686 (moderate confidence), which Talos assesses shares TTP, infrastructure, and victimology overlaps with APT41 and UNC5174. Post-exploitation, UAT-9686 deployed a persistent Python backdoor (AquaShell) embedded into the appliance's existing EUQ web server file at /data/web/euq_webui/htdocs/index.py, a compiled Go ELF reverse-SSH tunneling implant derived from the open-source ReverseSSH project (AquaTunnel), the open-source Chisel tunneling tool for pivoting into internal networks, and a log-sanitization utility (AquaPurge) that uses egrep-style keyword filtering to strip incriminating lines from appliance logs. Exploitation requires the Spam Quarantine feature to be enabled and its EUQ/administrative interface exposed to the internet — not the default configuration, which limits the vulnerable population but does not reduce severity for exposed appliances. CISA added CVE-2025-20393 to the Known Exploited Vulnerabilities catalog on 2025-12-17 with a Federal Civilian Executive Branch remediation deadline of 2025-12-24. No workaround exists; Cisco recommends taking the Spam Quarantine feature off the internet, restricting access to trusted hosts, and rebuilding/reimaging any appliance confirmed compromised, since AquaShell and AquaTunnel persistence can survive simple config resets.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1059.006 Python
- T1059.004 Unix Shell
- T1505.003 Web Shell
- T1554 Compromise Host Software Binary
- T1068 Exploitation for Privilege Escalation
- T1685.006 Clear Linux or Mac System Logs
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1572 Protocol Tunneling
- T1090 Proxy
- T1571 Non-Standard Port
- T1071.001 Web Protocols
- T1016 System Network Configuration Discovery
- T1570 Lateral Tool Transfer
- T1005 Data from Local System
- T1587.004 Exploits

## Sources

- [Pickling the Mailbox: A Deep Dive into CVE-2025-20393](https://starlabs.sg/blog/2026/02-pickling-the-mailbox-a-deep-dive-into-cve-2025-20393/)
- [Cisco Security Advisory: Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager (cisco-sa-sma-attack-N9bf4)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4)
- [CVE-2025-20393 Detail](https://nvd.nist.gov/vuln/detail/CVE-2025-20393)
- [CISA Known Exploited Vulnerabilities Catalog Entry](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-20393)
- [UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager](https://blog.talosintelligence.com/uat-9686/)
- [CVE-2025-20393 Exploitation: A Maximum-Severity Zero-Day Vulnerability in Cisco AsyncOS Software Abused in Attacks by the China-Backed APT UAT-9686](https://socprime.com/blog/cve-2025-20393-vulnerability-exploitation/)
- [Cisco Zero-Day Vulnerability (CVE-2025-20393) Exploited in the Wild](https://www.esentire.com/security-advisories/cisco-zero-day-vulnerability-cve-2025-20393-exploited-in-the-wild)
- [CVE-2025-20393: Threat Campaign Targeting Cisco Secure Email Gateway](https://arcticwolf.com/resources/blog/cve-2025-20393/)
- [China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear](https://www.securityweek.com/china-linked-hackers-exploiting-zero-day-in-cisco-security-gear/)
- [Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances](https://thehackernews.com/2025/12/cisco-warns-of-active-attacks.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1541
