Directory Permission Vulnerability in Cisco Desk and IP Phones
CVE-2025-20335
What is CVE-2025-20335?
A directory permission vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 allows unauthenticated remote attackers to write files to specific directories on affected devices. This issue arises due to insufficient authentication controls that could be exploited by sending crafted requests. To successfully exploit this vulnerability, Web Access must be enabled, which is disabled by default.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Session Initiation Protocol (SIP) Software 12.1(1)SR1
Cisco Session Initiation Protocol (SIP) Software 11.5(1)
Cisco Session Initiation Protocol (SIP) Software 10.3(2)
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved