ID

VAR-202509-2355


CVE

CVE-2025-20335


DESCRIPTION

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to perform arbitrary file writes to specific directories in the underlying operating system. Note: To exploit this vulnerability, Web Access must be enabled on the phone. Web Access is disabled by default.

Trust: 1.0

sources: NVD: CVE-2025-20335

AFFECTED PRODUCTS

vendor:ciscomodel:ip phone 8851scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9841scope:ltversion:3.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8861scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7841scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8865scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7861scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9851scope:ltversion:3.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9841scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8821scope:eqversion:11.0\(6\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:eqversion:2.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8841scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8845scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:ltversion:2.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9851scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9861scope:ltversion:3.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8851nrscope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9871scope:ltversion:3.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7811scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8851scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9861scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8861scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8811scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7861scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:ltversion:3.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8821scope:ltversion:11.0\(6\)

Trust: 1.0

vendor:ciscomodel:desk phone 9871scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7841scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8841scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8851nrscope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8865scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7811scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7821scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8811scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7821scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8845scope:eqversion:14.3\(1\)

Trust: 1.0

sources: NVD: CVE-2025-20335

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@cisco.com: CVE-2025-20335
value: MEDIUM

Trust: 1.0

psirt@cisco.com: CVE-2025-20335
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.1

Trust: 1.0

sources: NVD: CVE-2025-20335

PROBLEMTYPE DATA

problemtype:CWE-284

Trust: 1.0

sources: NVD: CVE-2025-20335

EXTERNAL IDS

db:NVDid:CVE-2025-20335

Trust: 1.0

sources: NVD: CVE-2025-20335

REFERENCES

url:https://sec.cloudapps.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-phone-write-g3kcc5df

Trust: 1.0

sources: NVD: CVE-2025-20335

SOURCES

db:NVDid:CVE-2025-20335

LAST UPDATE DATE

2026-01-14T23:53:00.992000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2025-20335date:2026-01-05T14:49:25.683

SOURCES RELEASE DATE

db:NVDid:CVE-2025-20335date:2025-09-03T18:15:34.393