PT-2025-7536 · Cisco · Cisco Desk Phone 9800 Series+1

Zach Sanchez

·

Published

2025-02-19

·

Updated

2025-12-15

·

CVE-2025-20158

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series (affected versions not specified)
Description A vulnerability in the debug shell of the affected devices could allow an authenticated, local attacker to access sensitive information on the device. The attacker must have valid administrative credentials with SSH access on the device. SSH access is disabled by default. This issue is due to insufficient validation of user-supplied input by the debug shell. An attacker could exploit this by sending a crafted SSH client command to the CLI, potentially allowing access to sensitive information on the underlying operating system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-05019
CVE-2025-20158

Affected Products

Cisco Desk Phone 9800 Series
Cisco Video Phone 8875