{"id":24933,"date":"2025-11-05T14:45:25","date_gmt":"2025-11-05T14:45:25","guid":{"rendered":"http:\/\/localhost\/?p=24933"},"modified":"2025-11-05T14:45:25","modified_gmt":"2025-11-05T14:45:25","slug":"cisco-unified-contact-center-express-remote-code-execution-vulnerability","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=24933","title":{"rendered":"Cisco Unified Contact Center Express Remote Code Execution Vulnerability_CVE-2025-20354"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and execute arbitrary commands with root permissions on an affected system.\\r\\n\\r\\nThis vulnerability is due to improper authentication mechanisms that are associated to specific Cisco Unified CCX features. An attacker could exploit this vulnerability by uploading a crafted file to an affected system through the Java RMI process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root.&#8221;,&#8221;published&#8221;:&#8221;2025-11-05T16:31:14.821Z&#8221;,&#8221;modified&#8221;:&#8221;2025-11-05T20:09:07.654Z&#8221;,&#8221;type&#8221;:&#8221;cve&#8221;,&#8221;title&#8221;:&#8221;Cisco Unified Contact Center Express Remote Code Execution Vulnerability&#8221;,&#8221;source&#8221;:&#8221;cisco&#8221;,&#8221;references&#8221;:&#8221;https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cc-unauth-rce-QeN8h7mQ&#8221;,&#8221;id&#8221;:&#8221;CVE-2025-20354&#8243;,&#8221;bulletinFamily&#8221;:&#8221;&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:null,&#8221;sourceData&#8221;:&#8221;Cisco Cisco Unified Contact Center Express 10.5(1)SU1\\nCisco Cisco Unified Contact Center Express 10.6(1)\\nCisco Cisco Unified Contact Center Express 11.6(1)\\nCisco Cisco Unified Contact Center Express 10.6(1)SU1\\nCisco Cisco Unified Contact Center Express 10.6(1)SU3\\nCisco Cisco Unified Contact Center Express 11.6(2)\\nCisco Cisco Unified Contact Center Express 12.0(1)\\nCisco Cisco Unified Contact Center Express 11.0(1)SU1\\nCisco Cisco Unified Contact Center Express 11.5(1)SU1\\nCisco Cisco Unified Contact Center Express 10.5(1)\\nCisco Cisco Unified Contact Center Express 12.5(1)\\nCisco Cisco Unified Contact Center Express 12.5(1)SU1\\nCisco Cisco Unified Contact Center Express 12.5(1)SU2\\nCisco Cisco Unified Contact Center Express 12.5(1)SU3\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES01\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES02\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES03\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES04\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES02\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU01_ES02\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU01_ES03\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES01\\nCisco Cisco Unified Contact Center Express 11.6(2)ES07\\nCisco Cisco Unified Contact Center Express 11.6(2)ES08\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU01_ES01\\nCisco Cisco Unified Contact Center Express 12.0(1)ES04\\nCisco Cisco Unified Contact Center Express 12.5(1)ES02\\nCisco Cisco Unified Contact Center Express 12.5(1)ES03\\nCisco Cisco Unified Contact Center Express 11.6(2)ES06\\nCisco Cisco Unified Contact Center Express 12.5(1)ES01\\nCisco Cisco Unified Contact Center Express 12.0(1)ES03\\nCisco Cisco Unified Contact Center Express 12.0(1)ES01\\nCisco Cisco Unified Contact Center Express 11.6(2)ES05\\nCisco Cisco Unified Contact Center Express 12.0(1)ES02\\nCisco Cisco Unified Contact Center Express 11.6(2)ES04\\nCisco Cisco Unified Contact Center Express 11.6(2)ES03\\nCisco Cisco Unified Contact Center Express 11.6(2)ES02\\nCisco Cisco Unified Contact Center Express 11.6(2)ES01\\nCisco Cisco Unified Contact Center Express 10.6(1)SU3ES03\\nCisco Cisco Unified Contact Center Express 11.0(1)SU1ES03\\nCisco Cisco Unified Contact Center Express 10.6(1)SU3ES01\\nCisco Cisco Unified Contact Center Express 10.5(1)SU1ES10\\nCisco Cisco Unified Contact Center Express 11.5(1)SU1ES03\\nCisco Cisco Unified Contact Center Express 11.6(1)ES02\\nCisco Cisco Unified Contact Center Express 11.5(1)ES01\\nCisco Cisco Unified Contact Center Express 10.6(1)SU2\\nCisco Cisco Unified Contact Center Express 10.6(1)SU2ES04\\nCisco Cisco Unified Contact Center Express 11.6(1)ES01\\nCisco Cisco Unified Contact Center Express 10.6(1)SU3ES02\\nCisco Cisco Unified Contact Center Express 11.5(1)SU1ES02\\nCisco Cisco Unified Contact Center Express 11.5(1)SU1ES01\\nCisco Cisco Unified Contact Center Express 11.0(1)SU1ES02\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES03\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES04\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES05\\nCisco Cisco Unified Contact Center Express UCCX 15.0.1\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES06&#8243;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:9.8,&#8221;severity&#8221;:&#8221;CRITICAL&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;&#8221;,&#8221;category_name&#8221;:&#8221;CVE&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;Cisco Unified Contact Center Express&#8221;,&#8221;version&#8221;:&#8221;10.5(1)SU1&#8243;,&#8221;vendor&#8221;:&#8221;Cisco&#8221;,&#8221;ai_description&#8221;:&#8221;AI processing failed &#8211; no valid JSON found&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[9,6,8,35,12,13,7,11,5],"class_list":["post-24933","post","type-post","status-publish","format-standard","hentry","category-category_cve","tag-critical","tag-cve","tag-cvss","tag-cvss-98","tag-exploit","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cisco Unified Contact Center Express Remote Code Execution Vulnerability_CVE-2025-20354 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=24933\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cisco Unified Contact Center Express Remote Code Execution Vulnerability_CVE-2025-20354 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=24933\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-05T14:45:25+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24933#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24933\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Cisco Unified Contact Center Express Remote Code Execution Vulnerability_CVE-2025-20354\",\"datePublished\":\"2025-11-05T14:45:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24933\"},\"wordCount\":658,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-9.8\",\"exploit\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_cve\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=24933#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24933\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24933\",\"name\":\"Cisco Unified Contact Center Express Remote Code Execution Vulnerability_CVE-2025-20354 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-11-05T14:45:25+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24933#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=24933\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24933#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cisco Unified Contact Center Express Remote Code Execution Vulnerability_CVE-2025-20354\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cisco Unified Contact Center Express Remote Code Execution Vulnerability_CVE-2025-20354 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=24933","og_locale":"en_US","og_type":"article","og_title":"Cisco Unified Contact Center Express Remote Code Execution Vulnerability_CVE-2025-20354 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and...","og_url":"https:\/\/zero.redgem.net\/?p=24933","og_site_name":"zero redgem","article_published_time":"2025-11-05T14:45:25+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=24933#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=24933"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Cisco Unified Contact Center Express Remote Code Execution Vulnerability_CVE-2025-20354","datePublished":"2025-11-05T14:45:25+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=24933"},"wordCount":658,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-9.8","exploit","news","Security","tapic","Vulnerability"],"articleSection":["category_cve"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=24933#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=24933","url":"https:\/\/zero.redgem.net\/?p=24933","name":"Cisco Unified Contact Center Express Remote Code Execution Vulnerability_CVE-2025-20354 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-11-05T14:45:25+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=24933#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=24933"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=24933#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Cisco Unified Contact Center Express Remote Code Execution Vulnerability_CVE-2025-20354"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/24933","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=24933"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/24933\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=24933"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=24933"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=24933"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}