Cisco Unified Communications Products Command Injection Vulnerability Allowing Arbitrary Command Execution as Root

Vulnerability

A command injection vulnerability has been identified in the command-line interface (CLI) of various Cisco Unified Communications products. This vulnerability allows an authenticated, local attacker to execute arbitrary commands on the underlying operating system of the affected device with root privileges. The issue arises from inadequate validation of user-supplied command arguments, enabling attackers to manipulate commands executed on the CLI. To exploit this vulnerability, an attacker must possess valid administrative credentials.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of commands on the affected device's operating system as the root user.

Remediation

Cisco has released software updates to address this vulnerability. Users are advised to consult the Cisco Security Advisories page for information on fixed releases and upgrade instructions.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
3.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.