Vulnerability record · CVE-2020-3161 · published 15 April 2020
CVE-2020-3161: Cisco IP Phones web server input validation flaw allows root RCE and DoS
Cisco · Ip Phone 8865 Firmware
The web server on multiple Cisco IP Phone models fails to properly validate HTTP requests, allowing a crafted request to trigger remote code execution with root privileges or a device reload. Because the flaw is reachable over the network without authentication, it exposes voice endpoints that are often placed on trusted internal networks.
Description
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable root code execution and DoS on widely deployed voice endpoints, with KEV listing and very high EPSS.
What it is
The web server on multiple Cisco IP Phone models fails to properly validate HTTP requests, allowing a crafted request to trigger remote code execution with root privileges or a device reload. Because the flaw is reachable over the network without authentication, it exposes voice endpoints that are often placed on trusted internal networks.
Impact
An unauthenticated attacker can execute code as root on the phone or force it to reload, causing a denial of service. Root access on a phone can be used to pivot, intercept or manipulate voice traffic, or disrupt telephony services.
Attack surface
Reached over the network via HTTP requests to the phone's web server; the CVSS vector shows no privileges or user interaction required. Any reachable phone web interface is a candidate target.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS 30-day probability is about 0.84 (99.7th percentile). A public exploit reference exists on Packet Storm, indicating exploit code is available.
What to do
- Apply the Cisco firmware updates referenced in the vendor security advisory cisco-sa-voip-phones-rce-dos-rB6EeRXs.
- Restrict network access to phone web servers using segmentation, ACLs, or management VLANs so only trusted hosts can reach them.
- Disable the phone web server where it is not operationally required.
- Monitor for and block crafted HTTP requests to phone web interfaces at network boundaries.
- Track KEV remediation deadlines and verify firmware versions across all listed phone models.
Detection
- Alert on HTTP requests to IP phone web servers containing unusual or malformed parameters, especially from non-management hosts.
- Monitor phone logs and syslog for unexpected reloads or crashes that correlate with inbound HTTP traffic.
- Baseline normal HTTP access to phone web interfaces and flag new or anomalous source IPs.
- Watch for signs of root-level activity or unexpected processes on phones, such as altered configuration or outbound connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-3161 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157265/Cisco-IP-Phone-11.7-Denial-Of-Service.html | ExploitThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs | Vendor Advisory |
| http://packetstormsecurity.com/files/157265/Cisco-IP-Phone-11.7-Denial-Of-Service.html | ExploitThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3161 | US Government Resource |
Track CVE-2020-3161 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-3161), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.