CVE-2025-20350

7.5

Cisco · Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875

A stack-based buffer overflow in the web UI of certain Cisco IP phones allows an unauthenticated remote attacker to trigger a device reload, resulting in a denial of service condition.

Executive summary

An unauthenticated remote denial of service vulnerability in Cisco SIP Software affects multiple desk and video phone series, posing a risk of operational disruption.

Vulnerability

The flaw is a stack-based buffer overflow (CWE-121) triggered when the device processes maliciously crafted HTTP packets. Exploitation is possible by an unauthenticated attacker, provided the device is registered to Cisco Unified Communications Manager and has the Web Access feature enabled.

Business impact

Successful exploitation results in an immediate device reload, leading to a denial of service. With a CVSS score of 7.5, this high-severity vulnerability could disrupt critical communication infrastructure, impacting organizational productivity and emergency response capabilities if these devices are relied upon for daily operations.

Remediation

Immediate Action: Review the official Cisco security advisory for available firmware updates and apply them to all affected devices. If updates are not immediately available, ensure Web Access is disabled on all devices to eliminate the primary attack vector.

Proactive Monitoring: Monitor network traffic for anomalous HTTP requests directed at IP phone management interfaces. Review system logs for unexpected device reboots or crash reports that may indicate exploitation attempts.

Compensating Controls: Implement network segmentation to isolate voice traffic from untrusted networks and restrict access to phone management interfaces via Access Control Lists (ACLs) to only authorized administrative subnets.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the ease of exploitation once the vulnerable conditions are met, organizations should prioritize auditing their phone fleets to identify devices with Web Access enabled. Disable this feature immediately on all production units until patches are verified and deployed to prevent unauthorized service disruption.

More Cisco CVEs

Sources