CVE-2026-20281: Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability
A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted HTTP packets to the device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, resulting in a DoS condition. A manual reboot of the device is required to recover from this condition. Note: For this vulnerability to be exploitable, the phone must be registered to Cisco Unified Communications Manager (Unified CM) and have Web Access enabled. Web Access is disabled by default.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Ensure Web Access is disabled (it is disabled by default). This reduces exposure because the vulnerability requires the phone to have Web Access enabled to be exploitable.
Cisco Desk Phone 9800 Series / Cisco IP Phone 7800 and 8800 Series / Cisco Video Phone 8875 (SIP Software) Web Access = disabled - Compensating control
If Web Access is required, restrict access to the phone’s Web interface so it is not reachable from untrusted networks (because an unauthenticated attacker can send a continuous stream of crafted HTTP packets to trigger the DoS).
- Operational
If devices are affected and enter the continuous memory consumption/DoS state, perform a manual reboot of the device to recover.
Event History
Frequently Asked Questions
Which deployments are exposed to exploitation?
An affected phone must be running Cisco SIP Software, registered to Cisco Unified Communications Manager, and have Web Access enabled. Web Access is disabled by default, so devices using the default setting are not exploitable through this issue.
What does an attacker need to do to trigger the denial of service?
The attacker does not need authentication or user interaction. They must be able to send a continuous stream of crafted HTTP packets to the affected device.
What is the operational impact and recovery action?
Successful exploitation causes the phone to continuously consume memory until it enters a denial-of-service condition. Recovery requires a manual reboot of the affected device.
What mitigation is available if a fix cannot be deployed immediately?
Disable Web Access on affected phones where it is not required. Because Web Access is a prerequisite for exploitation and is disabled by default, this prevents exploitation through the described attack path.