CVE-2025-20236 - CVE House
Back to Database
Status published High CVE-2025-20236

Cisco Webex App Client-Side Remote Code Execution Vulnerability

Vulnerability Description

A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-20236

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Webex Teams
Vulnerable Versions:
44.6, 44.6.0.29928, 44.6.0.30148, 44.7, 44.7.0.30141, 44.7.0.30285

Timeline

Official Publish: April 16th, 2025
Last Modified: February 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.