The US Cybersecurity and Infrastructure Security Agency (CISA) has published a security alert just as vulnerabilities impacting ASUS, Cisco and SonicWall users were confirmed as being actively exploited in the wild. Here’s what you need to do as soon as possible.
Although the CISA’s Known Exploited Vulnerabilities (KEV) Catalog is best known for being associated with Binding Operational Directive (BOD) 22-01 that requires certain US federal agencies to respond and patch systems within a short mandatory timeframe, 24 December in this case, that doesn’t mean other organisations can ignore it. Far from it, in fact. As CISA itself says, “these types of vulnerabilities are frequent attack vectors for malicious cyber actors,” and as such pose a significant risk to all enterprises.
The December 17 security advisory alert strongly urged “all organisations to reduce their exposure to cyberattacks by prioritising timely remediation” of the following three vulnerabilities:
- CVE-2025-20393: An improper input validation vulnerability, which has been given the maximum Common Vulnerability Scoring System (CVSS) severity rating of 10/10. This affects Cisco’s Secure Email Gateway and Web Manager appliances.
- CVE-2025-40602: A missing authorisation vulnerability, which “only” has a 6.6 CVSS rating but is known as being chained in exploits with the 9.8-rated CVE-2025-23006 if not already patched. It affects SonicWall’s SMA1000 appliances.
- CVE-2025-59374: An embedded malicious code vulnerability, with a CVSS rating of 9.3, affecting the ASUS Live Update client that reached end of support status way back in 2021.
Cisco vulnerability tops the CISA list
You have probably realised that it’s the first of these, the Cisco vulnerability, that’s the most critical here, and not just because it hits the magic 10 CVSS rating.
CVE-2025-20393, Cisco has confirmed, provides “a persistence mechanism planted by the threat actors to maintain a degree of control over compromised appliances,” and there is no patch yet available. Instead, Cisco strongly recommended “following a multi-step process to restore the appliance to a secure configuration, when possible,” if the appliance is identified as having either the web management interface or the Spam Quarantine port exposed to and reachable from the internet.
As for the other two, look, I get it. I know what you are thinking. If granny had wheels, she would be a bicycle. But just because one of these exploits targets a long-past-sell-by-date service and another requires a vulnerability patched in January to be doable, doesn’t mean you safely can ignore the CISA alert.
If organisations were on top of their patch management systems, such alerts would not be issued. If all enterprises had already taken the necessary precautions by patching these vulnerabilities, attackers would not be wasting time on finding ways to exploit them.
More articles by security expert Davey Winder