CVE-2026-20281: Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

Published Sep 2, 2026
·
Updated

A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted HTTP packets to the device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, resulting in a DoS condition. A manual reboot of the device is required to recover from this condition. Note: For this vulnerability to be exploitable, the phone must be registered to Cisco Unified Communications Manager (Unified CM) and have Web Access enabled. Web Access is disabled by default.

Affected Software

3 affected components
Cisco Cisco Desk Phone 9800 Series
Cisco Cisco IP Phone 7800 and 8800 Series
Cisco Cisco Video Phone 8875

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Ensure Web Access is disabled (it is disabled by default). This reduces exposure because the vulnerability requires the phone to have Web Access enabled to be exploitable.

    Cisco Desk Phone 9800 Series / Cisco IP Phone 7800 and 8800 Series / Cisco Video Phone 8875 (SIP Software) Web Access = disabled
  2. Compensating control

    If Web Access is required, restrict access to the phone’s Web interface so it is not reachable from untrusted networks (because an unauthenticated attacker can send a continuous stream of crafted HTTP packets to trigger the DoS).

  3. Operational

    If devices are affected and enter the continuous memory consumption/DoS state, perform a manual reboot of the device to recover.

Event History

Sep 2, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to exploitation?

An affected phone must be running Cisco SIP Software, registered to Cisco Unified Communications Manager, and have Web Access enabled. Web Access is disabled by default, so devices using the default setting are not exploitable through this issue.

2

What does an attacker need to do to trigger the denial of service?

The attacker does not need authentication or user interaction. They must be able to send a continuous stream of crafted HTTP packets to the affected device.

3

What is the operational impact and recovery action?

Successful exploitation causes the phone to continuously consume memory until it enters a denial-of-service condition. Recovery requires a manual reboot of the affected device.

4

What mitigation is available if a fix cannot be deployed immediately?

Disable Web Access on affected phones where it is not required. Because Web Access is a prerequisite for exploitation and is disabled by default, this prevents exploitation through the described attack path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203