Directory Permission Vulnerability in Cisco Desk and IP Phones
CVE-2025-20335

5.3MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
3 September 2025

Badges

👾 Exploit Exists

What is CVE-2025-20335?

A directory permission vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 allows unauthenticated remote attackers to write files to specific directories on affected devices. This issue arises due to insufficient authentication controls that could be exploited by sending crafted requests. To successfully exploit this vulnerability, Web Access must be enabled, which is disabled by default.

Affected Version(s)

Cisco Session Initiation Protocol (SIP) Software 12.1(1)SR1

Cisco Session Initiation Protocol (SIP) Software 11.5(1)

Cisco Session Initiation Protocol (SIP) Software 10.3(2)

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20335 : Directory Permission Vulnerability in Cisco Desk and IP Phones