Insufficient Input Validation in Cisco Video Phone and Desk Phone Products
CVE-2025-20158
What is CVE-2025-20158?
A flaw in the debug shell of certain Cisco Video Phones and Desk Phones allows an authenticated, local attacker with valid SSH credentials to gain unauthorized access to sensitive information on the device. The exploitation is made possible due to inadequate validation of commands supplied by the user. Although SSH access is disabled by default, attackers could circumvent this restriction, potentially exposing critical system data by sending specially crafted commands to the device's command-line interface.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Session Initiation Protocol (SIP) Software 3.1(1)
Cisco Session Initiation Protocol (SIP) Software 3.0(1)
Cisco Session Initiation Protocol (SIP) Software 2.3(1)
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved