URL Redirection Vulnerability in Cisco Webex Meetings
CVE-2025-20291

4.3MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
3 September 2025

Badges

👾 Exploit Exists

What is CVE-2025-20291?

A vulnerability in Cisco Webex Meetings enables an unauthenticated, remote attacker to exploit insufficient URL validation in meeting-join links. By crafting a malicious join URL, the attacker could redirect a targeted user to a potentially harmful website, which might mislead the user into thinking it is a legitimate Webex page. This exploit heightens the risk of phishing attacks, as users may inadvertently provide sensitive information on the fraudulent site. Cisco has implemented measures to mitigate this risk, eliminating the need for customer action.

Affected Version(s)

Cisco Webex Meetings

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20291 : URL Redirection Vulnerability in Cisco Webex Meetings