Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 Directory Permission Vulnerability Allowing Arbitrary File Write

Vulnerability

A vulnerability exists in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875, all running Cisco SIP Software. This vulnerability allows an unauthenticated, remote attacker to write arbitrary files on the affected device. The issue arises from inadequate authentication controls, enabling attackers to send crafted requests that exploit this vulnerability. Successful exploitation could result in unauthorized file writes to specific directories within the device's operating system. Notably, Web Access must be enabled on the phone for exploitation to occur, as this feature is disabled by default.

Impact

Exploitation of this vulnerability could lead to unauthorized file writes on the affected device, potentially allowing for the introduction of malicious files or the modification of existing files in a way that could disrupt normal operation or compromise security.

Remediation

Cisco has released software updates to address this vulnerability. Users should consult the Cisco Security Advisories page for information on fixed releases and upgrade instructions.

Added: Sep 3, 2025, 6:24 PM
Updated: Sep 3, 2025, 6:24 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
7.0
remediation
0.0
relevance
0.5
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.