A backdoor account that would have given remote attackers root access to unpatched devices has been eliminated by Cisco from its Unified Communications Manager (Unified CM).
Call routing, device administration, and telephony functions are handled by Cisco Unified Communications Manager (CUCM), formerly known as Cisco CallManager, which acts as the central control system for Cisco’s IP telephony systems.
Static root account user credentials, which were meant to be used during development and testing, are the cause of the vulnerability (recorded as CVE-2025-20309), which was assigned a maximum severity rating.
A Cisco security advisory issued on Wednesday states that, irrespective of device configuration, CVE-2025-20309 impacts Cisco Unified CM and Unified CM SME Engineering Special (ES) releases 15.0.1.13010-1 through 15.0.1.13017-1.
There are no workarounds for the vulnerability, the business added. The only way for administrators to address the issue and eliminate the backdoor account read more about Cisco warns that Unified CM has hardcoded root SSH credentials.
