CVE-2025-20158 describes a sensitive information disclosure vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series. An authenticated, local attacker with administrative SSH credentials can exploit insufficient input validation to access underlying operating system information. This vulnerability has a CVSS score of 4.4 (MEDIUM) due to its local attack vector and high impact on confidentiality, though SSH access is disabled by default, increasing complexity. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:video_phone_8875_firmware:*:*:*:*:*:*:*:* | ||
< 3.3\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:desk_phone_9871_firmware:*:*:*:*:*:*:*:* | ||
< 3.3\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:desk_phone_9841_firmware:*:*:*:*:*:*:*:* | ||
< 3.3\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:desk_phone_9851_firmware:*:*:*:*:*:*:*:* | ||
< 3.3\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:desk_phone_9861_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.