CVE-2025-20158
A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials with SSH access on the affected device. SSH access is disabled by default. This vulnerability is due to insufficient validation of user-supplied input by the debug shell of an affected device. An attacker could exploit this vulnerability by sending a crafted SSH client command to the CLI. A successful exploit could allow the attacker to access sensitive information on the underlying operating system.
Published:Feb 19, 2025
Last Modified:Dec 15, 2025
EPS:Feb 19, 2025
EPSS Score:0.00033
CVSS Score:4.4
Affected Products
Vendor
Product
Action
Vendor
Cisco
Product
Desk Phone 9841
Cisco
Desk Phone 9841
Vendor
Cisco
Product
Desk Phone 9841 Firmware
Cisco
Desk Phone 9841 Firmware
Vendor
Cisco
Product
Desk Phone 9851
Cisco
Desk Phone 9851
Vendor
Cisco
Product
Desk Phone 9851 Firmware
Cisco
Desk Phone 9851 Firmware
Vendor
Cisco
Product
Desk Phone 9861
Cisco
Desk Phone 9861
Vendor
Cisco
Product
Desk Phone 9861 Firmware
Cisco
Desk Phone 9861 Firmware
Vendor
Cisco
Product
Desk Phone 9871
Cisco
Desk Phone 9871
Vendor
Cisco
Product
Desk Phone 9871 Firmware
Cisco
Desk Phone 9871 Firmware
Vendor
Cisco
Product
Video Phone 8875
Cisco
Video Phone 8875
Vendor
Cisco
Product
Video Phone 8875 Firmware
Cisco
Video Phone 8875 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
