CVE-2025-20351
published 2025-10-15CVE-2025-20351: A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could…
PriorityP433medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.27%
18.5th percentile
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the web UI.
This vulnerability exists because the web UI of an affected device does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Note: To exploit this vulnerability, the phone must be registered to Cisco Unified Communications Manager and have Web Access enabled. Web Access is disabled by default.
Affected
136 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Vulnerabilities
vendor_cisco·2025-10-15·CVSS 7.5
CVE-2025-20350 [HIGH] CWE-121 Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Vulnerabilities
Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Vulnerabilities
Multiple vulnerabilities in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or conduct a cross-site scripting (XSS) attack against a user of the web UI.
Note: To exploit these vulnerabilities, the phone must be registered to Cisco Unified Communications Manager and have Web Access enabled. Web Access is disabled by default.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilitie
Cisco
Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20351 Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Vulnerabilities
CVE-2025-20351: Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Vulnerabilities
Multiple vulnerabilities in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or conduct a cross-site scripting (XSS) attack against a user of the web UI. Note: To exploit these vulnerabilities, the phone must be registered to Cisco Unified Communications Manager and have Web Access enabled. Web Access is disabled by default. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-121, CWE-79, CWE-121, CWE-79
Bug IDs: CSCwn51601, CSCwn51683, CSCwn58
GHSA
GHSA-q352-cxfj-h569: A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Softw
ghsa_unreviewed·2025-10-15
CVE-2025-20351 [MEDIUM] CWE-79 GHSA-q352-cxfj-h569: A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Softw
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the web UI.
This vulnerability exists because the web UI of an affected device does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Note: To exploit this vulnerability, the phone must be registered to Cisco Unified Communications Manager and have Web Access enabled. Web Access is disabled by defau
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-15
Published