March 24, 2015 By Douglas Bonderud 2 min read

Cisco may want to cover its ears; concerned businesses will likely have a lot to say after it was revealed that the technology firm’s IP phones are vulnerable to remote eavesdropping. As reported by Threatpost, the issue was found by Chris Watts, an Australian technology researcher. While Cisco says it is working on a new firmware version to fix the problem, what is the risk to companies using these mobile devices in the meantime?

Hear No Evil?

According to an advisory from Cisco, “A vulnerability in the firmware of the Cisco Small Business SPA 300 and 500 series IP phones could allow an unauthenticated, remote attacker to listen to the audio stream of an IP phone.”

The problem stems from an issue with authentication settings in the phone’s default configuration, allowing attackers to send a malicious XML request to these devices. In turn, this grants remote access to audio streams and the ability to make phone calls remotely.

This sounds scary, especially since the Version 7.5.5 firmware for Cisco Small Business SPA500 IP phones doesn’t yet have a fix. However, the company says there is a silver lining, since privileged access might be required to exploit the bug at any stage.

“An attacker may need access to trusted, internal networks behind a firewall to send crafted XML requests,” Cisco noted. The word “may” is worrisome, since it implies that in some cases, high-level access might not be mandatory. It is also worth noting that another bug was discovered in both the SPA300 and 500 series phones, allowing malicious actors to carry out cross-site scripting attacks.

Speak No Evil?

This isn’t the first instance of eavesdropping in recent months. As noted by Digital Trends, several SIM card manufacturers reported in February that the National Security Agency had tried — and supposedly failed — to hack these ID cards to gain access to millions of consumer phones. And, in an even stranger case, Mashable reports Mattel’s new Hello Barbie toy is coming under fire because it eavesdrops on children by listening to what they say and then sends this data to a cloud server, where it is ostensibly used to prompt better responses from the doll. Some security experts say the toy is a privacy violation because there is no guarantee this data will be used ethically.

Companies and citizens alike don’t enjoy having their conversations tapped, even if the likelihood is slim or there are assurances the data will be safeguarded. Cisco’s vulnerability came at a critical time, since businesses are looking for ways to lock down private interactions and ensure any technology they use comes with the best protection possible. Even if the risk is slim, the fact that IP phones are now under threat of eavesdropping is hard for companies to hear.

More from

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today