Cisco has warned users of a vulnerability concerning Unified Communications Manager (Unified CM), part of the control system for Cisco's IP telephony systems.
Affecting Cisco Unified CM and Cisco Unified Communications Manager Session Management Edition (Unified CM SME), the bug could allow an unauthenticated, remote attacker to log in to an affected device using the root account.
Tracked as CVE-2025-20309, the vulnerability was revealed on Tuesday and marked as Critical by the networking giant. Cisco explained that the flaw is due to the presence of static user credentials for the root account that are reserved for use during development.
“An attacker could exploit this vulnerability by using the account to log in to an affected system,” Cisco said in a statement. “A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user.”
The affected Cisco Unified CM and Unified CM SME Engineering Special (ES) releases include 15.0.1.13010-1 through 15.0.1.13017-1, regardless of device configuration.
To address the flaw, Cisco recommended upgrading vulnerable devices to Cisco Unified CM and Unified CM SME 15SU3 (July 2025) or by applying a patch file.
Beyond the patches, the firm said there are no workarounds that address this vulnerability.
The security issue comes less than a week after critical identity issues affecting Cisco releases, with both instances once again only involving the latest versions of Cisco software.
Comments