Cisco has issued a security advisory for multiple vulnerabilities in the Desk Phone 9800 Series, IP Phone 7800 and 8800 Series , and Video Phone 8875 models that run Cisco Session Initiation Protocol (SIP) software .
See also: Cisco SNMP vulnerability used to install Linux rootkits

The advisory, published on October 15, 2025, details vulnerabilities that could allow unauthenticated remote attackers to trigger denial of service (DoS) or cross-site scripting (XSS) attacks via the web user interface of the devices. These flaws affect phones registered with Cisco Unified Communications Manager (CUCM) with Web Access, a feature that is disabled by default to minimize exposure.
The main concern is CVE-2025-20350, a high severity buffer overflow bug with a CVSS 3.1 score of 7.5. This vulnerability occurs when affected devices process crafted HTTP packets, potentially causing the phone to reboot and stop working. Attackers do not need privileges and can exploit it over the network with low complexity, leading to temporary unavailability of communication services.
See also: Coordinated attack on Cisco, Fortinet and Palo Alto Networks devices

Cisco links this to several bug IDs, including CSCwn51601, highlighting its impact on enterprise telephony environments. A secondary issue, CVE-2025-20351, introduces a medium severity XSS vulnerability with a CVSS score of 6.1. Due to insufficient input validation in the web user interface, attackers can inject malicious scripts by tricking users into clicking on crafted links.
Successful exploitation could steal session data or manipulate the interface, although it requires user interaction. Related bugs include CSCwn51683, which highlights persistent vulnerabilities in web manipulation. These vulnerabilities target specific versions of Cisco SIP software across the aforementioned phone series, excluding those on Multiplatform Firmware, the advisory states.
The exploit relies on active web access and CUCM registration, conditions that are not met in typical configurations. No public exploits or malicious uses have been reported, but organizations with web-enabled features face increased risks in unified communications networks.
See also: 48+ Cisco Firewalls vulnerable to active zero-day vulnerability

Cisco does not provide immediate solutions beyond disabling Web Access through CUCM management or the Bulk Management Tool, which administrators can verify by checking the phone IP in a browser. Patched releases include SIP Software 3.3(1) for the 9800 Desk Phone and 8875 Video Phone, 14.3(1)SR2 for the 7800/8800 IP Phone , and 11.0(6)SR7 for the 8821 IP Phone.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
