PT-2025-16791 · Cisco · Cisco Webex App
Published
2025-04-16
·
Updated
2026-04-16
·
CVE-2025-20236
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Webex App versions 44.6 through 44.7
Cisco Webex App (affected versions not specified)
Description
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user. Over 10,000 services are potentially affected.
Recommendations
For versions 44.6 and 44.7, update to version 44.8 or later to protect against potential threats.
As a temporary workaround, consider restricting access to the
meeting invite link feature until a patch is available.
Avoid using the meeting invite link feature in the affected API endpoint until the issue is resolved.
For all versions, apply the latest security patches provided by Cisco to safeguard systems.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Webex App