Directory Permission Vulnerability in Cisco Desk and IP Phones
CVE-2025-20335
5.3MEDIUM
What is CVE-2025-20335?
A directory permission vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 allows unauthenticated remote attackers to write files to specific directories on affected devices. This issue arises due to insufficient authentication controls that could be exploited by sending crafted requests. To successfully exploit this vulnerability, Web Access must be enabled, which is disabled by default.
Affected Version(s)
Cisco Session Initiation Protocol (SIP) Software 12.1(1)SR1
Cisco Session Initiation Protocol (SIP) Software 11.5(1)
Cisco Session Initiation Protocol (SIP) Software 10.3(2)