XSS Vulnerability in Cisco Desk Phone 9800 Series and IP Phone Models
CVE-2025-20351

6.1MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
15 October 2025

Badges

👾 Exploit Exists

What is CVE-2025-20351?

A vulnerability exists in the web UI of the Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875. Due to insufficient validation of user-supplied input, an unauthenticated remote attacker could execute arbitrary script code via a crafted link. This could allow access to sensitive browser-based information if the phones are registered to Cisco Unified Communications Manager with Web Access enabled, which is disabled by default.

Affected Version(s)

Cisco Session Initiation Protocol (SIP) Software 12.1(1)SR1

Cisco Session Initiation Protocol (SIP) Software 11.5(1)

Cisco Session Initiation Protocol (SIP) Software 10.3(2)

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20351 : XSS Vulnerability in Cisco Desk Phone 9800 Series and IP Phone Models