← Back

CVE-2025-20236

nvd nist
Published: Apr 16, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user.

Affected (6)

Products: Cisco: Webex Teams
1 product
Webex Teams
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 44.6.0.29928
Version 44.6.0.30148
Version 44.6
Version 44.7.0.30141
Version 44.7.0.30285
Version 44.7

Timeline

No history available yet.