Cisco released security updates to address vulnerabilities in its IP Phone 7800 and 8800 series that could be exploited by remote, unauthenticated attackers. The flaws result from improper validation of user-supplied input during the authentication process. The most severe vulnerabilities in Cisco 8800 Series IP Phones could allow attackers to conduct a cross-site request forgery attack or write arbitrary files to the systems disk. The vulnerabilities are rated with the highest severity score, 8.1 out of 10.”]
Source: https://securityaffairs.co/wordpress/82752/security/cisco-ip-phone-8800-flaws.html