Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Vulnerabilities
TL;DR 📌
- Multiple vulnerabilities in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or conduct a cross-site scripting (XSS) attack against a user of the web UI.…
- Highest CVSS: 7.5 (High).
- Fix available — see the first fixed release below.
- CVEs: CVE-2025-20350, CVE-2025-20351.
What it is
Two independent vulnerabilities affect the web UI of Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 running Cisco SIP Software. They do not depend on each other, and a release fixed for one may still be exposed to the other.
CVE-2025-20350 is a buffer overflow triggered when the phone’s web UI processes HTTP packets. An unauthenticated, remote attacker can send crafted HTTP input to the device to cause it to reload, producing a denial of service. No user interaction is required (CVSS 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-20351 is a cross-site scripting flaw caused by insufficient input validation in the web UI. Exploitation requires persuading a user to click a crafted link; a successful attack runs arbitrary script in the context of the web UI or accesses browser-based session information (CVSS 6.1, AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Both require the phone to be registered to Cisco Unified Communications Manager and to have Web Access enabled — a setting that is disabled by default. Cisco confirms that IP Phone 7800 and 8800 Series running Multiplatform Firmware are not affected; only the SIP Software builds are in scope.
What to do
- Check whether Web Access is enabled on affected phones: press the gear icon, go to Admin settings > Network Setup, note the IP address, then browse to that address from a device with network access. If the Device Information screen loads, Web Access is on.
- If Web Access isn’t needed, disable it via Cisco Unified Communications Manager (Device > Phone > find device > toggle Web Access to Disabled > Save). For fleets, use the Bulk Admin Tool (BAT) rather than doing this device by device. Cisco states this mitigates both issues, though there is no formal workaround for the underlying flaws.
- Plan to upgrade regardless of the mitigation, since Cisco has released fixed SIP Software:
- Desk Phone 9800 Series and Video Phone 8875 on release 3: upgrade to 3.3(1) for both CVEs.
- IP Phone 7800/8800 on release 14.3: 14.3(1)SR2 fixes CVE-2025-20350; migrate to a fixed release for CVE-2025-20351 (14.4 line, where 14.4(1) fixes it and 14.4 is not vulnerable to the DoS issue).
- IP Phone 7800/8800 on releases earlier than 14.3, and Video Phone 8875 on 2.3(1)SR1 and earlier: migrate to a fixed release — the advisory does not treat these as remediable in place.
- IP Phone 8821 on release 11: upgrade to 11.0(6)SR7 for both CVEs; releases earlier than 11 need migration to a fixed release.
- Confirm the phone model against the advisory’s product list before assuming it’s affected — Multiplatform Firmware builds of the 7800/8800 series are explicitly out of scope.
Fixed releases
| Affected release | First fixed release |
|---|---|
| 3 | 3.3(1) |
For leadership 🧭
Executive summary. Cisco Desk Phone 9800, IP Phone 7800/8800, and Video Phone 8875 units running SIP Software can be crashed remotely by an unauthenticated attacker if Web Access is enabled on the device, and a related flaw allows script injection against a user who clicks a crafted link. Neither issue has a formal workaround beyond disabling Web Access, so phones with it turned on should be checked and, where possible, patched at the next opportunity.
Why it matters:
- CVE-2025-20350 lets an unauthenticated remote attacker send crafted HTTP input to the phone’s web UI and force a reload, taking the handset out of service with no login or user action needed.
- CVE-2025-20351 needs a user to click a crafted link but then runs arbitrary script in the phone’s web UI, exposing browser-based session information tied to that interface.
- Both flaws only bite phones registered to Cisco Unified Communications Manager with Web Access enabled — a setting off by default, so exposure hinges entirely on whether it was switched on for admin or support convenience.
- IP Phone 7800/8800 units running Multiplatform Firmware rather than SIP Software are confirmed unaffected, so scope is narrower than the full model list suggests.
Now / Next / Later:
- Now: Check each affected phone model for Web Access status via the gear icon and Admin settings menu, or query the setting centrally through Unified Communications Manager, to identify which units are actually exposed.
- Next: Disable Web Access via Unified Communications Manager (using the Bulk Admin Tool for fleets) on any phone that doesn’t genuinely need it, and schedule firmware upgrades to the fixed SIP Software releases for the remaining devices.
- Later: Set Web Access to disabled as the standard baseline in Unified Communications Manager device templates for these phone lines, so future deployments don’t inherit unnecessary exposure by mistake.