Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-20236


A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user.


Published

2025-04-16T17:15:49.573

Last Modified

2025-08-01T21:03:51.873

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-829

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco webex_teams 44.6 Yes
Application cisco webex_teams 44.6.0.29928 Yes
Application cisco webex_teams 44.6.0.30148 Yes
Application cisco webex_teams 44.7 Yes
Application cisco webex_teams 44.7.0.30141 Yes
Application cisco webex_teams 44.7.0.30285 Yes

References