CVE-2025-20156 is a critical privilege escalation vulnerability in the REST API of Cisco Meeting Management, allowing low-privileged authenticated attackers to gain administrator access. This flaw, rated 9.9 CRITICAL on CVSS, stems from improper authorization enforcement, enabling attackers to send specific API requests and achieve full control over managed edge nodes. While not currently listed in KEV, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness, though no public exploit code (Metasploit, Nuclei, ExploitDB) is yet available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.9.1CPE matchmatch criteria | cpe:2.3:a:cisco:meeting_management:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.