Cisco IP Phones Hit with High-Severity Denial-of-Service Flaw
Cisco has disclosed a high-severity vulnerability affecting its range of IP and video phones that could allow an unauthenticated remote attacker to cause devices to become unavailable.
The issue, tracked as CVE-2026-20281, carries a CVSS score of 7.5 out of 10 and is classified as a high-severity denial-of-service flaw caused by improper memory management when affected devices process HTTP packets.
An attacker could exploit the vulnerability by sending a continuous stream of specially crafted HTTP packets to a vulnerable phone, forcing it to continuously consume memory until it enters a denial-of-service condition.
The vulnerability affects Cisco devices running its Session Initiation Protocol (SIP) software, including the Desk Phone 9800 Series, IP Phone 7800 Series, and Wireless IP Phone 8821. However, for the attack to work, the phone must be registered with Cisco Unified Communications Manager (Unified CM) and Web Access must be enabled.