Cisco Removes Backdoor Account That Gave Hackers Root Access to Unified CM Systems


# Cisco Removes Critical Backdoor Account from Unified Communications Manager

Cisco has eliminated a dangerous backdoor account from its Unified Communications Manager (Unified CM) that could have allowed remote attackers to gain complete control of vulnerable devices.

## The Vulnerability

The security flaw, designated CVE-2025-20309, received the maximum severity rating due to hardcoded root account credentials that were originally intended for development and testing purposes. These static credentials could not be changed or deleted by administrators, creating a permanent security risk.

Cisco Unified Communications Manager, formerly known as Cisco CallManager, serves as the central control system for Cisco’s IP telephony networks, managing call routing, device operations, and telephony features across enterprise environments.

## Affected Systems

The vulnerability impacts:
– Cisco Unified CM releases 15.0.1.13010-1 through 15.0.1.13017-1
– Unified CM SME Engineering Special (ES) versions within the same range
– All device configurations regardless of setup

## Attack Potential

Successful exploitation would allow unauthenticated remote attackers to:
– Log in using the backdoor root account
– Execute arbitrary commands with full administrative privileges
– Gain complete control over affected communication systems

While Cisco’s security team has not detected active exploitation or public proof-of-concept code, the company has provided detection methods for administrators.

## Detection and Remediation

**Detection Method:**
Administrators can check for potential exploitation attempts by examining system logs. Successful attacks create entries in `/var/log/active/syslog/secure` that can be retrieved using the command: `file get activelog syslog/secure`

**Fix Options:**
– Upgrade to Cisco Unified CM and Unified CM SME 15SU3 (available July 2025)
– Apply the CSCwp27755 patch file immediately
– No workarounds are available for this vulnerability

## Recurring Security Pattern

This incident represents part of a troubling pattern for Cisco, which has discovered similar backdoor accounts in multiple products over recent years, including:
– IOS XE devices
– Wide Area Application Services (WAAS)
– Digital Network Architecture (DNA) Center
– Emergency Responder software
– Smart Licensing Utility (CSLU)

## Immediate Action Required

Organizations using affected Cisco Unified Communications Manager versions should prioritize patching immediately, as no alternative security measures can address this critical vulnerability. The presence of unchangeable backdoor credentials poses an unacceptable risk to enterprise communication infrastructure.

Share This Article