Critical Cisco Vulnerability in Unified CM Exposes Root Access and Urges Phone Replacement
Originally Published 6 months ago — by The Hacker News

Cisco has issued security updates for a critical vulnerability (CVE-2025-20309) in Unified Communications Manager that allows attackers to gain root access using static credentials, potentially leading to severe network compromise. The flaw affects multiple versions and was discovered during internal testing, with no evidence of active exploitation yet.

