Description
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the web UI.

This vulnerability exists because the web UI of an affected device does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Note: To exploit this vulnerability, the phone must be registered to Cisco Unified Communications Manager and have Web Access enabled. Web Access is disabled by default.
Published: 2025-10-15
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 04 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco desk Phone 9841
Cisco desk Phone 9841 Firmware
Cisco desk Phone 9851
Cisco desk Phone 9851 Firmware
Cisco desk Phone 9861
Cisco desk Phone 9861 Firmware
Cisco desk Phone 9871
Cisco desk Phone 9871 Firmware
Cisco ip Phone 7811
Cisco ip Phone 7811 Firmware
Cisco ip Phone 7821
Cisco ip Phone 7821 Firmware
Cisco ip Phone 7841
Cisco ip Phone 7841 Firmware
Cisco ip Phone 7861
Cisco ip Phone 7861 Firmware
Cisco ip Phone 8811
Cisco ip Phone 8811 Firmware
Cisco ip Phone 8821
Cisco ip Phone 8821 Firmware
Cisco ip Phone 8832
Cisco ip Phone 8832 Firmware
Cisco ip Phone 8841
Cisco ip Phone 8841 Firmware
Cisco ip Phone 8845
Cisco ip Phone 8845 Firmware
Cisco ip Phone 8851
Cisco ip Phone 8851 Firmware
Cisco ip Phone 8861
Cisco ip Phone 8861 Firmware
Cisco ip Phone 8865
Cisco ip Phone 8865 Firmware
Cisco video Phone 8875 Firmware
CPEs cpe:2.3:h:cisco:desk_phone_9841:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:desk_phone_9851:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:desk_phone_9861:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:desk_phone_9871:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_phone_7811:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_phone_7821:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_phone_7841:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_phone_7861:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_phone_8811:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_phone_8821:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_phone_8832:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_phone_8841:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_phone_8845:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_phone_8851:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_phone_8861:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_phone_8865:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:video_phone_8875:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:desk_phone_9841_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:desk_phone_9851_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:desk_phone_9861_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:desk_phone_9871_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7811_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7811_firmware:14.3\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7811_firmware:14.3\(1\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7821_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7821_firmware:14.3\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7821_firmware:14.3\(1\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7841_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7841_firmware:14.3\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7841_firmware:14.3\(1\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7861_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7861_firmware:14.3\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7861_firmware:14.3\(1\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8811_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8811_firmware:14.3\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8811_firmware:14.3\(1\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(0.7\):mpp:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(2\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(2\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(2\):sr2:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(3\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(3\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(3\):sr2:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(3\):sr3:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(3\):sr4:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(3\):sr5:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(3\):sr6:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(4\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(4\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(4\):sr2:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(4\):sr3:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(5\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(5\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(5\):sr2:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(5\):sr3:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(6\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(6\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(6\):sr2:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(6\):sr4:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(6\):sr5:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(6\):sr6:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8832_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8832_firmware:14.3\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8832_firmware:14.3\(1\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8841_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8841_firmware:14.3\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8841_firmware:14.3\(1\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8845_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8845_firmware:14.3\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8845_firmware:14.3\(1\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8851_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8851_firmware:14.3\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8851_firmware:14.3\(1\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8861_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8861_firmware:14.3\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8861_firmware:14.3\(1\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8865_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8865_firmware:14.3\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8865_firmware:14.3\(1\):sr1:*:*:*:*:*:*
cpe:2.3:o:cisco:video_phone_8875_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:video_phone_8875_firmware:2.3\(1\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:video_phone_8875_firmware:2.3\(1\):sr1:*:*:*:*:*:*
Vendors & Products Cisco desk Phone 9841
Cisco desk Phone 9841 Firmware
Cisco desk Phone 9851
Cisco desk Phone 9851 Firmware
Cisco desk Phone 9861
Cisco desk Phone 9861 Firmware
Cisco desk Phone 9871
Cisco desk Phone 9871 Firmware
Cisco ip Phone 7811
Cisco ip Phone 7811 Firmware
Cisco ip Phone 7821
Cisco ip Phone 7821 Firmware
Cisco ip Phone 7841
Cisco ip Phone 7841 Firmware
Cisco ip Phone 7861
Cisco ip Phone 7861 Firmware
Cisco ip Phone 8811
Cisco ip Phone 8811 Firmware
Cisco ip Phone 8821
Cisco ip Phone 8821 Firmware
Cisco ip Phone 8832
Cisco ip Phone 8832 Firmware
Cisco ip Phone 8841
Cisco ip Phone 8841 Firmware
Cisco ip Phone 8845
Cisco ip Phone 8845 Firmware
Cisco ip Phone 8851
Cisco ip Phone 8851 Firmware
Cisco ip Phone 8861
Cisco ip Phone 8861 Firmware
Cisco ip Phone 8865
Cisco ip Phone 8865 Firmware
Cisco video Phone 8875 Firmware

Tue, 21 Oct 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco ip Phone 7800
Cisco ip Phone 8800
Cisco ip Phone 8800 Series
Cisco session Initiation Protocol (sip) Firmware
Cisco video Phone 8875
Vendors & Products Cisco
Cisco ip Phone 7800
Cisco ip Phone 8800
Cisco ip Phone 8800 Series
Cisco session Initiation Protocol (sip) Firmware
Cisco video Phone 8875

Wed, 15 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the web UI. This vulnerability exists because the web UI of an affected device does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Note: To exploit this vulnerability, the phone must be registered to Cisco Unified Communications Manager and have Web Access enabled. Web Access is disabled by default.
Title Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Firmware Cross-Site Scripting Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Cisco Desk Phone 9841 Desk Phone 9841 Firmware Desk Phone 9851 Desk Phone 9851 Firmware Desk Phone 9861 Desk Phone 9861 Firmware Desk Phone 9871 Desk Phone 9871 Firmware Ip Phone 7800 Ip Phone 7811 Ip Phone 7811 Firmware Ip Phone 7821 Ip Phone 7821 Firmware Ip Phone 7841 Ip Phone 7841 Firmware Ip Phone 7861 Ip Phone 7861 Firmware Ip Phone 8800 Ip Phone 8800 Series Ip Phone 8811 Ip Phone 8811 Firmware Ip Phone 8821 Ip Phone 8821 Firmware Ip Phone 8832 Ip Phone 8832 Firmware Ip Phone 8841 Ip Phone 8841 Firmware Ip Phone 8845 Ip Phone 8845 Firmware Ip Phone 8851 Ip Phone 8851 Firmware Ip Phone 8861 Ip Phone 8861 Firmware Ip Phone 8865 Ip Phone 8865 Firmware Session Initiation Protocol (sip) Firmware Video Phone 8875 Video Phone 8875 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2025-10-15T17:43:25.544Z

Reserved: 2024-10-10T19:15:13.257Z

Link: CVE-2025-20351

cve-icon Vulnrichment

Updated: 2025-10-15T17:43:19.926Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-15T17:15:49.060

Modified: 2025-12-04T21:26:51.467

Link: CVE-2025-20351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-21T09:41:07Z

Weaknesses