Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cisco Desk, IP, and Video Phone Vulnerabilities Let Remote Attackers Trigger DoS And XSS Attacks

On Tue, Oct 15, 2025, Cisco issued a security advisory addressing multiple vulnerabilities identified in its Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 models operating with the Cisco Session Initiation Protocol (SIP)…

On Tue, Oct 15, 2025, Cisco issued a security advisory addressing multiple vulnerabilities identified in its Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 models operating with the Cisco Session Initiation Protocol (SIP) Software.

The advisory highlights potential risks where unauthenticated remote attackers could exploit these vulnerabilities to initiate denial-of-service (DoS) conditions or cross-site scripting (XSS) attacks through the devices' web user interface.

These security issues are relevant to phones registered with Cisco Unified Communications Manager (CUCM) that have Web Access enabled, a feature that is disabled by default to limit exposure.

The primary vulnerability, identified as CVE-2025-20350, involves a high-severity buffer overflow flaw with a CVSS 3.1 score of 7.5. This flaw is triggered when affected devices process specially crafted HTTP packets, which could result in the phone reloading and disrupting operations. The exploitation is possible over the network with low complexity and does not require any privileges, potentially causing temporary unavailability of communication services.

The primary vulnerability, identified as CVE-2025-20350, involves a high-severity buffer overflow flaw with a CVSS 3.1 score of 7.5.
Stephen Gale · Thehackingpost

This vulnerability is linked to several bug IDs, including CSCwn51601, underscoring its impact on enterprise telephony environments. Another identified issue, CVE-2025-20351, introduces a medium-severity XSS vulnerability with a CVSS score of 6.1.

The XSS vulnerability arises due to inadequate input validation in the web UI, allowing attackers to inject malicious scripts by tricking users into clicking crafted links. Successful exploitation could lead to session data theft or interface manipulation, although it necessitates user interaction. Related bugs include CSCwn51683, indicating persistent weaknesses in web handling.

These vulnerabilities affect specific Cisco SIP Software releases across the mentioned phone series, excluding those on Multiplatform Firmware. Exploitation requires active Web Access and CUCM registration, conditions not typically met in standard configurations. No public exploits have been reported, but organizations with enabled web features may face increased risks.

Advertisement

Cisco recommends disabling Web Access via CUCM administration or the Bulk Administration Tool as a precautionary measure. Administrators can verify this by checking the phone's IP in a browser.

Fixed software releases include SIP Software 3.3(1) for Desk Phone 9800 and Video Phone 8875, 14.3(1)SR2 for IP Phone 7800/8800, and 11.0(6)SR7 for IP Phone 8821. Users are advised to upgrade to these versions promptly to prevent potential disruptions, as the patches address the vulnerabilities without affecting core functionality.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories