Cisco Desk, IP, and Video Phone Vulnerabilities Let Remote Attackers Trigger DoS And XSS Attacks
On Tue, Oct 15, 2025, Cisco issued a security advisory addressing multiple vulnerabilities identified in its Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 models operating with the Cisco Session Initiation Protocol (SIP)…
On Tue, Oct 15, 2025, Cisco issued a security advisory addressing multiple vulnerabilities identified in its Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 models operating with the Cisco Session Initiation Protocol (SIP) Software.
The advisory highlights potential risks where unauthenticated remote attackers could exploit these vulnerabilities to initiate denial-of-service (DoS) conditions or cross-site scripting (XSS) attacks through the devices' web user interface.
These security issues are relevant to phones registered with Cisco Unified Communications Manager (CUCM) that have Web Access enabled, a feature that is disabled by default to limit exposure.
The primary vulnerability, identified as CVE-2025-20350, involves a high-severity buffer overflow flaw with a CVSS 3.1 score of 7.5. This flaw is triggered when affected devices process specially crafted HTTP packets, which could result in the phone reloading and disrupting operations. The exploitation is possible over the network with low complexity and does not require any privileges, potentially causing temporary unavailability of communication services.
The primary vulnerability, identified as CVE-2025-20350, involves a high-severity buffer overflow flaw with a CVSS 3.1 score of 7.5.
This vulnerability is linked to several bug IDs, including CSCwn51601, underscoring its impact on enterprise telephony environments. Another identified issue, CVE-2025-20351, introduces a medium-severity XSS vulnerability with a CVSS score of 6.1.
The XSS vulnerability arises due to inadequate input validation in the web UI, allowing attackers to inject malicious scripts by tricking users into clicking crafted links. Successful exploitation could lead to session data theft or interface manipulation, although it necessitates user interaction. Related bugs include CSCwn51683, indicating persistent weaknesses in web handling.
These vulnerabilities affect specific Cisco SIP Software releases across the mentioned phone series, excluding those on Multiplatform Firmware. Exploitation requires active Web Access and CUCM registration, conditions not typically met in standard configurations. No public exploits have been reported, but organizations with enabled web features may face increased risks.
Cisco recommends disabling Web Access via CUCM administration or the Bulk Administration Tool as a precautionary measure. Administrators can verify this by checking the phone's IP in a browser.
Fixed software releases include SIP Software 3.3(1) for Desk Phone 9800 and Video Phone 8875, 14.3(1)SR2 for IP Phone 7800/8800, and 11.0(6)SR7 for IP Phone 8821. Users are advised to upgrade to these versions promptly to prevent potential disruptions, as the patches address the vulnerabilities without affecting core functionality.
Based on reporting by Cyber Security News.
