Cisco has released security updates to address multiple high-severity vulnerabilities affecting its Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, IP Phone 8821, and Video Phone 8875 products. The most notable flaw, tracked as CVE-2025-20350, is a denial-of-service (DoS) vulnerability that could allow remote attackers to disrupt the normal operation of affected devices. According to Cisco's advisories, the vulnerabilities impact devices running versions prior to 3.3(1) for the Desk Phone 9800 Series, prior to 14.4(1) for the IP Phone 7800 and 8800 Series, prior to 11.0(6)SR7 for the IP Phone 8821, and prior to 3.3(1) for the Video Phone 8875. The Canadian Centre for Cyber Security (CCCS) has also issued an alert, urging organizations to review Cisco's advisories and apply the recommended patches and mitigations without delay. The vulnerabilities include both denial-of-service and information disclosure issues, with some flaws related to SIP software and others affecting the underlying RoomOS and TelePresence Collaboration Endpoint software. Cisco's advisories detail that exploitation of these vulnerabilities could result in service interruptions, potentially impacting business communications and operations. The company has provided specific version updates to remediate the risks, and administrators are advised to upgrade to the latest secure releases. The advisories also mention vulnerabilities in Cisco's Snort 3 software, but the primary focus is on the telephony products. No active exploitation of these vulnerabilities has been reported at the time of the advisories, but the critical nature of the flaws warrants immediate attention. The updates are part of Cisco's ongoing efforts to address security weaknesses in its widely deployed communication devices. Organizations using affected Cisco phone models should prioritize patching to prevent potential denial-of-service attacks that could disrupt voice and video communications. The CCCS highlights the importance of following Cisco's mitigation guidance to ensure continued secure operation of telephony infrastructure. Cisco's prompt response and detailed advisories provide clear remediation steps for network administrators. The vulnerabilities underscore the need for regular patch management and vigilance in monitoring vendor security updates. Failure to address these issues could expose organizations to service outages and potential information leaks. The advisories serve as a reminder of the critical role that secure communication endpoints play in enterprise environments. By applying the recommended patches, organizations can mitigate the risk of disruption and maintain the integrity of their communication systems.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Cisco issued software fixes for CVE-2025-20350, addressing the denial-of-service vulnerability in affected Cisco Desk Phones and Cisco IP Phones. The patch release date is identified in reporting as October 17, 2025.
Cisco published a vulnerability report for CVE-2025-20350, a high-severity denial-of-service flaw affecting Cisco Desk Phones and Cisco IP Phones. A Canadian Centre for Cyber Security alert also referenced the Cisco security advisory AV25-672.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.