PT-2025-7536 · Cisco · Cisco Desk Phone 9800 Series+1
Zach Sanchez
·
Published
2025-02-19
·
Updated
2025-12-15
·
CVE-2025-20158
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series (affected versions not specified)
Description
A vulnerability in the debug shell of the affected devices could allow an authenticated, local attacker to access sensitive information on the device. The attacker must have valid administrative credentials with SSH access on the device. SSH access is disabled by default. This issue is due to insufficient validation of user-supplied input by the debug shell. An attacker could exploit this by sending a crafted SSH client command to the CLI, potentially allowing access to sensitive information on the underlying operating system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Desk Phone 9800 Series
Cisco Video Phone 8875