Cisco BroadWorks CommPilot Application Software Cross-Site Scripting Vulnerability

🚨SEVERITY: MEDIUM β€” CVSS 4.8Security Advisory

TL;DR πŸ“Œ

  • A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this…
  • Highest CVSS: 4.8 (Medium).
  • Fix available β€” see the first fixed release below.
  • CVEs: CVE-2025-20307.

What it is

CVE-2025-20307 is a stored cross-site scripting flaw in the web-based management interface of Cisco BroadWorks CommPilot Application Software. Insufficient input validation on certain pages allows malicious script to be injected and later executed in the browser of another user of that interface.

Exploitation requires an authenticated attacker with valid administrative credentials β€” this is not an unauthenticated, pre-login flaw. The CVSS vector confirms low attack complexity, network access, but high privileges required and user interaction needed, with the scope changed. In practice, an attacker who already holds admin-level access to CommPilot can plant script that runs in the context of the interface when viewed by another logged-in user, potentially letting them execute arbitrary script or pull sensitive browser-based session data.

The CommPilot Application is affected regardless of device configuration, and Cisco notes it ships both as a standalone package and bundled with the BroadWorks Application Server or BroadWorks Xtended Services Platform, so exposure isn’t limited to one deployment model.

Cisco’s PSIRT states it is not aware of any public announcements or malicious use of this vulnerability, and it is not listed in CISA’s KEV catalogue.

What to do

  • Upgrade CommPilot Application Release 24.0 to 24.0.2025.05, and Release 26.0 to 26.0.2025.05.
  • If running Release 23.0 or 25.0, migrate to a fixed release β€” Cisco does not provide a patched build for these lines.
  • Where CommPilot is bundled with the BroadWorks Application Server, upgrade any release earlier than RI.2025.05 to RI.2025.05.
  • Where bundled with BroadWorks Xtended Services Platform, upgrade any release earlier than RI.2025.08 to RI.2025.08.
  • There are no workarounds; patching is the only remediation Cisco offers.
  • Since exploitation requires valid administrative credentials, review who holds admin access to CommPilot and tighten credential hygiene as a complementary control while patches are rolled out.

Fixed releases

Affected release First fixed release
24.0 24.0.2025.05
26.0 26.0.2025.05

For leadership 🧭

Executive summary. Cisco’s BroadWorks CommPilot admin interface can be used to plant malicious script that executes in another administrator’s browser session, potentially exposing session data, but only an attacker who already holds valid admin credentials can trigger it. There is no known exploitation and no workaround, so this should be scheduled into the next patch cycle rather than treated as an emergency.

Why it matters:

  • Affects the CommPilot web management interface used to administer BroadWorks-based voice services, whether run standalone or bundled with the Application Server or Xtended Services Platform.
  • A successful attack lets one authenticated admin execute script in the browser session of another admin viewing the same interface, potentially harvesting session data.
  • Releases 23.0 and 25.0 have no patched build at all β€” the only remediation is migrating off those lines entirely.
  • No workaround exists, so unpatched systems remain exposed for as long as the upgrade is delayed.

Now / Next / Later:

  • Now: Identify which CommPilot release, and any bundled BroadWorks Application Server or Xtended Services Platform release, is currently running, and check whether it falls below the fixed versions.
  • Next: Patch CommPilot 24.0 to 24.0.2025.05 or 26.0 to 26.0.2025.05, upgrade Application Server builds earlier than RI.2025.05, and Xtended Services Platform builds earlier than RI.2025.08; if running 23.0 or 25.0, plan migration to a supported release.
  • Later: Review and restrict who holds administrative credentials for CommPilot, since exploitation depends entirely on an attacker already having admin-level access to the interface.

Source