← Vulnerability feed

Vulnerability record · CVE-2020-3161 · published 15 April 2020

CVE-2020-3161: Cisco IP Phones web server input validation flaw allows root RCE and DoS

Cisco · Ip Phone 8865 Firmware

The web server on multiple Cisco IP Phone models fails to properly validate HTTP requests, allowing a crafted request to trigger remote code execution with root privileges or a device reload. Because the flaw is reachable over the network without authentication, it exposes voice endpoints that are often placed on trusted internal networks.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 84% · top 0.3% CWE-20 · Improper input validation
9.8CVSS 3.1 base score, v2 10.0
84%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
13Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable root code execution and DoS on widely deployed voice endpoints, with KEV listing and very high EPSS.

What it is

The web server on multiple Cisco IP Phone models fails to properly validate HTTP requests, allowing a crafted request to trigger remote code execution with root privileges or a device reload. Because the flaw is reachable over the network without authentication, it exposes voice endpoints that are often placed on trusted internal networks.

Impact

An unauthenticated attacker can execute code as root on the phone or force it to reload, causing a denial of service. Root access on a phone can be used to pivot, intercept or manipulate voice traffic, or disrupt telephony services.

Attack surface

Reached over the network via HTTP requests to the phone's web server; the CVSS vector shows no privileges or user interaction required. Any reachable phone web interface is a candidate target.

Exploitation

Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS 30-day probability is about 0.84 (99.7th percentile). A public exploit reference exists on Packet Storm, indicating exploit code is available.

What to do

  • Apply the Cisco firmware updates referenced in the vendor security advisory cisco-sa-voip-phones-rce-dos-rB6EeRXs.
  • Restrict network access to phone web servers using segmentation, ACLs, or management VLANs so only trusted hosts can reach them.
  • Disable the phone web server where it is not operationally required.
  • Monitor for and block crafted HTTP requests to phone web interfaces at network boundaries.
  • Track KEV remediation deadlines and verify firmware versions across all listed phone models.

Detection

  • Alert on HTTP requests to IP phone web servers containing unusual or malformed parameters, especially from non-management hosts.
  • Monitor phone logs and syslog for unexpected reloads or crashes that correlate with inbound HTTP traffic.
  • Baseline normal HTTP access to phone web interfaces and flag new or anomalous source IPs.
  • Watch for signs of root-level activity or unexpected processes on phones, such as altered configuration or outbound connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-3161 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3161 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-20078Cisco ip phone 6871 firmware stack-based buffer overflow vulnerabilityMultiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute …EPSS 10%8.8CVE-2022-20968Cisco ip phone 7811 firmware out-of-bounds write vulnerabilityA vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, ad…EPSS 6.1%8.8CVE-2020-3111Cisco ip conference phone 7832 firmware improper input validation vulnerabilityA vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely e…EPSS 3.1%8.1CVE-2022-20774Cisco ip phone 6871 firmware insufficient verification of data authenticity vulnerabilityA vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauth…EPSS 0.40%7.5CVE-2025-20350Cisco desk phone 9871 firmware stack-based buffer overflow vulnerabilityA vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Soft…EPSS 0.48%7.5CVE-2025-20336Cisco desk phone 9841 firmware information exposure vulnerabilityA vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could a…EPSS 0.39%7.5CVE-2023-20079Cisco ip phone 6871 firmware stack-based buffer overflow vulnerabilityMultiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute …EPSS 10%7.5CVE-2019-1922Cisco ip conference phone 7832 firmware null pointer dereference vulnerabilityA vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to caus…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2020-3161), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.