CVE-2025-20236

A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:webex_teams:44.6:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_teams:44.6.0.29928:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_teams:44.6.0.30148:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_teams:44.7:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_teams:44.7.0.30141:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_teams:44.7.0.30285:*:*:*:*:*:*:*

History

01 Aug 2025, 21:03

Type Values Removed Values Added
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-client-rce-ufyMMYLC - () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-client-rce-ufyMMYLC - Vendor Advisory
First Time Cisco webex Teams
Cisco
CPE cpe:2.3:a:cisco:webex_teams:44.7:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_teams:44.7.0.30285:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_teams:44.6.0.29928:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_teams:44.7.0.30141:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_teams:44.6.0.30148:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_teams:44.6:*:*:*:*:*:*:*

16 Apr 2025, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : unknown
CWE CWE-829
Summary A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user. A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user.

16 Apr 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-16 17:15

Updated : 2025-08-01 21:03


NVD link : CVE-2025-20236

Mitre link : CVE-2025-20236


JSON object : View

Products Affected

cisco

  • webex_teams
CWE

No CWE.