Cisco has patched a critical vulnerability in its Unified CM and Unified CM SME software caused by hardcoded SSH credentials that let attackers log in as root.

Tracked as CVE-2025-20309 with a flawless 10/10 CVSS score, the flaw stems from static credentials embedded for development that were never meant to stay—but did.

The bug impacts Engineering Special versions 15.0.1.13010-1 through 15.0.1.13017-1, regardless of system configuration, and could allow full command execution with root privileges.

Cisco released a patch and plans to include the fix in the Unified CM 15SU3 update expected later this July.

Organizations are urged to check system logs for root access attempts in /var/log/active/syslog/secure to detect potential breaches.

The company claims no known exploitation in the wild, so for now, it’s only a ticking time bomb.

Three additional medium-severity flaws were also patched in Cisco Spaces Connector, ECE, and BroadWorks, covering privilege escalation and XSS vulnerabilities.

Cisco says none of these issues have been exploited—yet—but encourages users to update before attackers get any bright ideas.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Who we are

Established in 2022, TBC News is one of the Philippines’ leading digital news organizations covering business, technology, luxury, and the influential people and companies shaping the world.

With a growing international readership, TBC News delivers authoritative reporting, exclusive insights, and sharp perspectives on the developments driving industries, markets, and culture forward.

From groundbreaking innovations and major corporate developments to luxury, investment, and emerging trends, TBC News provides a distinctive editorial lens on the stories that matter most to decision-makers, industry leaders, and globally minded readers.

For more information, visit tbc-news.com.

Let’s connect

Discover more from TBC News

Subscribe now to keep reading and get access to the full archive.

Continue reading