{"id":24934,"date":"2025-11-05T14:45:30","date_gmt":"2025-11-05T14:45:30","guid":{"rendered":"http:\/\/localhost\/?p=24934"},"modified":"2025-11-05T14:45:30","modified_gmt":"2025-11-05T14:45:30","slug":"cisco-unified-contact-center-express-editor-authentication-bypass-vulnerability","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=24934","title":{"rendered":"Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability_CVE-2025-20358"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution.\\r\\n\\r\\nThis vulnerability is due to improper authentication mechanisms in the communication between the CCX Editor and an affected Unified CCX server. An attacker could exploit this vulnerability by redirecting the authentication flow to a malicious server and tricking the CCX Editor into believing the authentication was successful. A successful exploit could allow the attacker to create and execute arbitrary scripts on the underlying operating system of an affected Unified CCX server, as an internal non-root user account.&#8221;,&#8221;published&#8221;:&#8221;2025-11-05T16:31:23.210Z&#8221;,&#8221;modified&#8221;:&#8221;2025-11-05T20:09:52.833Z&#8221;,&#8221;type&#8221;:&#8221;cve&#8221;,&#8221;title&#8221;:&#8221;Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability&#8221;,&#8221;source&#8221;:&#8221;cisco&#8221;,&#8221;references&#8221;:&#8221;https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cc-unauth-rce-QeN8h7mQ&#8221;,&#8221;id&#8221;:&#8221;CVE-2025-20358&#8243;,&#8221;bulletinFamily&#8221;:&#8221;&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:null,&#8221;sourceData&#8221;:&#8221;Cisco Cisco Unified Contact Center Express 10.5(1)SU1\\nCisco Cisco Unified Contact Center Express 10.6(1)\\nCisco Cisco Unified Contact Center Express 11.6(1)\\nCisco Cisco Unified Contact Center Express 10.6(1)SU1\\nCisco Cisco Unified Contact Center Express 10.6(1)SU3\\nCisco Cisco Unified Contact Center Express 11.6(2)\\nCisco Cisco Unified Contact Center Express 12.0(1)\\nCisco Cisco Unified Contact Center Express 11.0(1)SU1\\nCisco Cisco Unified Contact Center Express 11.5(1)SU1\\nCisco Cisco Unified Contact Center Express 10.5(1)\\nCisco Cisco Unified Contact Center Express 12.5(1)\\nCisco Cisco Unified Contact Center Express 12.5(1)SU1\\nCisco Cisco Unified Contact Center Express 12.5(1)SU2\\nCisco Cisco Unified Contact Center Express 12.5(1)SU3\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES01\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES02\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES03\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES04\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES02\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU01_ES02\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU01_ES03\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES01\\nCisco Cisco Unified Contact Center Express 11.6(2)ES07\\nCisco Cisco Unified Contact Center Express 11.6(2)ES08\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU01_ES01\\nCisco Cisco Unified Contact Center Express 12.0(1)ES04\\nCisco Cisco Unified Contact Center Express 12.5(1)ES02\\nCisco Cisco Unified Contact Center Express 12.5(1)ES03\\nCisco Cisco Unified Contact Center Express 11.6(2)ES06\\nCisco Cisco Unified Contact Center Express 12.5(1)ES01\\nCisco Cisco Unified Contact Center Express 12.0(1)ES03\\nCisco Cisco Unified Contact Center Express 12.0(1)ES01\\nCisco Cisco Unified Contact Center Express 11.6(2)ES05\\nCisco Cisco Unified Contact Center Express 12.0(1)ES02\\nCisco Cisco Unified Contact Center Express 11.6(2)ES04\\nCisco Cisco Unified Contact Center Express 11.6(2)ES03\\nCisco Cisco Unified Contact Center Express 11.6(2)ES02\\nCisco Cisco Unified Contact Center Express 11.6(2)ES01\\nCisco Cisco Unified Contact Center Express 10.6(1)SU3ES03\\nCisco Cisco Unified Contact Center Express 11.0(1)SU1ES03\\nCisco Cisco Unified Contact Center Express 10.6(1)SU3ES01\\nCisco Cisco Unified Contact Center Express 10.5(1)SU1ES10\\nCisco Cisco Unified Contact Center Express 11.5(1)SU1ES03\\nCisco Cisco Unified Contact Center Express 11.6(1)ES02\\nCisco Cisco Unified Contact Center Express 11.5(1)ES01\\nCisco Cisco Unified Contact Center Express 10.6(1)SU2\\nCisco Cisco Unified Contact Center Express 10.6(1)SU2ES04\\nCisco Cisco Unified Contact Center Express 11.6(1)ES01\\nCisco Cisco Unified Contact Center Express 10.6(1)SU3ES02\\nCisco Cisco Unified Contact Center Express 11.5(1)SU1ES02\\nCisco Cisco Unified Contact Center Express 11.5(1)SU1ES01\\nCisco Cisco Unified Contact Center Express 11.0(1)SU1ES02\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES03\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES04\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES05\\nCisco Cisco Unified Contact Center Express UCCX 15.0.1\\nCisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES06&#8243;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:9.4,&#8221;severity&#8221;:&#8221;CRITICAL&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:L&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;&#8221;,&#8221;category_name&#8221;:&#8221;CVE&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;Cisco Unified Contact Center Express&#8221;,&#8221;version&#8221;:&#8221;10.5(1)SU1&#8243;,&#8221;vendor&#8221;:&#8221;Cisco&#8221;,&#8221;ai_description&#8221;:&#8221;AI processing failed &#8211; no valid JSON found&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[9,6,8,131,12,13,7,11,5],"class_list":["post-24934","post","type-post","status-publish","format-standard","hentry","category-category_cve","tag-critical","tag-cve","tag-cvss","tag-cvss-94","tag-exploit","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability_CVE-2025-20358 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=24934\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability_CVE-2025-20358 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=24934\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-05T14:45:30+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24934#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24934\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability_CVE-2025-20358\",\"datePublished\":\"2025-11-05T14:45:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24934\"},\"wordCount\":675,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-9.4\",\"exploit\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_cve\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=24934#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24934\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24934\",\"name\":\"Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability_CVE-2025-20358 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-11-05T14:45:30+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24934#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=24934\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=24934#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability_CVE-2025-20358\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability_CVE-2025-20358 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=24934","og_locale":"en_US","og_type":"article","og_title":"Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability_CVE-2025-20358 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain...","og_url":"https:\/\/zero.redgem.net\/?p=24934","og_site_name":"zero redgem","article_published_time":"2025-11-05T14:45:30+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=24934#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=24934"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability_CVE-2025-20358","datePublished":"2025-11-05T14:45:30+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=24934"},"wordCount":675,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-9.4","exploit","news","Security","tapic","Vulnerability"],"articleSection":["category_cve"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=24934#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=24934","url":"https:\/\/zero.redgem.net\/?p=24934","name":"Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability_CVE-2025-20358 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-11-05T14:45:30+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=24934#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=24934"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=24934#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability_CVE-2025-20358"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/24934","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=24934"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/24934\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=24934"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=24934"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=24934"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}