CVE-2025-20351: Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Firmware Cross-Site Scripting Vulnerability
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the web UI. This vulnerability exists because the web UI of an affected device does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Note: To exploit this vulnerability, the phone must be registered to Cisco Unified Communications Manager and have Web Access enabled. Web Access is disabled by default.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20351?
CVE-2025-20351 is classified as a high severity vulnerability due to the potential for unauthenticated remote attackers to conduct XSS attacks.
How do I fix CVE-2025-20351?
To fix CVE-2025-20351, update the affected Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 to the latest available firmware as provided by Cisco.
What are the affected products for CVE-2025-20351?
The affected products for CVE-2025-20351 include the Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 Series, Cisco IP Phone 8800 Series, and Cisco Video Phone 8875.
Can CVE-2025-20351 be exploited remotely?
Yes, CVE-2025-20351 can be exploited remotely by an unauthenticated attacker through the web UI.
What type of attacks can occur due to CVE-2025-20351?
CVE-2025-20351 can allow attackers to conduct Cross-Site Scripting (XSS) attacks against users of the web UI.