CVE-2015-6403: Cisco SPA300 Firmware

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan horse image by leveraging shell access, aka Bug ID CSCut67400.

Affected products

  • Cisco SPA300 Firmware: version 7.5.7 only
  • Cisco SPA500 Firmware: version 7.5.7 only

Published 2015-12-15. Last modified 2026-06-17.