PT-2025-16791 · Cisco · Cisco Webex App

Published

2025-04-16

·

Updated

2026-04-16

·

CVE-2025-20236

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Webex App versions 44.6 through 44.7 Cisco Webex App (affected versions not specified)
Description A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user. Over 10,000 services are potentially affected.
Recommendations For versions 44.6 and 44.7, update to version 44.8 or later to protect against potential threats. As a temporary workaround, consider restricting access to the meeting invite link feature until a patch is available. Avoid using the meeting invite link feature in the affected API endpoint until the issue is resolved. For all versions, apply the latest security patches provided by Cisco to safeguard systems.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-04707
CVE-2025-20236

Affected Products

Cisco Webex App