Cisco · Cisco Desk Phone 9800 Series · CVE-2025-20158
**Name of the Vulnerable Software and Affected Versions**
Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series (affected versions not specified)
**Description**
A vulnerability in the debug shell of the affected devices could allow an authenticated, local attacker to access sensitive information on the device. The attacker must have valid administrative credentials with SSH access on the device. SSH access is disabled by default. This issue is due to insufficient validation of user-supplied input by the debug shell. An attacker could exploit this by sending a crafted SSH client command to the CLI, potentially allowing access to sensitive information on the underlying operating system.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.