u/0xReadingSteiner

Is r/Cisco open? Or are they keeping me from posting there? Anyway, I will find a way to get the message out.

They got the almighty Mythos 5 and billions in infrastructure. I had a Chinese model that barely works and a toaster for a laptop. For them it's just "Mythos, find the vulnerability," "Mythos, fix the vulnerability," "Mythos, push the fix." So you have to wonder where are all those AI billions actually going? The vulnerabilities are still unpatched, and there's been no disclosure about how customers and networks are exposed, or since when. Keep going down this road and you are basically handing out the Decryption Key to everybody. If AI builds it, AI can find the flaws.

You may own the code. You may own the pipelines... the restaurant.  but I was the one cooking the burgers every day.

And you can't help but wonder: is this profiting off vulnerabilities? To stay secure you have to be on the latest version (which probably ships with a whole new set of undisclosed bugs), which means planning insane maintenance windows, then living through the phase where everything is broken and business operations get disrupted. All for what? A rushed release that never accounted for what the customer actually needs? Just hardening piled on top of hardening? And let's not even get into the service contracts, how much are the new licenses per device? How much is the new software? Sounds like a loop to me: stable operations -> mandatory upgrade -> six months of planning -> everything crashing every other day -> use the support contract they sold you -> repeat next year. Meanwhile you're exposed for half the cycle.

I can't wait to go public. I'm counting the days. But I have to be patient, the lawyers are making sure you can't pull anything sneaky to come after me. You may not answer me here, but we will drag you into a court of law. You might be so intoxicated with yourself, but let's see if you think you are above a judge.

Where is my last paycheck? It's been months. Who gave you the right to withhold my money... MY BREAD? We don't have slavery in this country anymore, the founding fathers took care of that. You think you get to play with people lives? My family? but don't worry. I'm a real man, and a man always provides no matter what. Even if I have to DoorDash 14 hours a day to put food on the table, I will. I always do... especially when I'm going up against somebody bigger than me.

I can't wait for trial. I can't wait for every piece of proof and evidence I have to become public record, the phone calls, the messages, all the communications. I can't wait to finally be able to talk about it. You can try to stop it, but people are going to want to hear it, and I know there are others out there who will like to come on my show and talk about what they have had to put up with.

And to everybody else reading this: really think about it. If you are not in a glass office, or if you have many peers, the layoffs are coming sooner or later. Don't be a fool. Save everything, every piece of proof, every evidence... because God forbid you may need it one day and don't have it.

Next drop as usual Monday at 23:59 PM UCT at reddit r/CiscoUC

reddit.com
u/0xReadingSteiner — 8 days ago

1,300+ Cisco Expressways on Shodan with 5060/5061 ports open. Two CVSS 9+ zero-days drop Monday 23:59 UTC. This is the why.

I used to work on these systems. I know how they're built because I supported them. When I started seeing problems, I tried to raise it. Then the next round of layoffs came and I was out. So I set up a lab at home and kept going. Three months, 55 vulnerabilities across UC, every channel I could find to report them. Nothing back.

I kept trying the right way. The proper path. Followed every bounty program, every proper disclosure process. But how weird that it seems like these programs are always rejecting critical software. And their replies were the most concerning part for me, "The vendor has paused the program." "The vendor is unresponsive." The bounty programs want to disclose. The cybersecurity researchers want to disclose. Yet no sign of communication from the vendor.

The crazy part is that I heard the rumors in the hallways. I didn't pay attention. I kept thinking, "This is a big tech company. The budget is already allocated. I don't think the higher-ups would want to cheap out on cybersecurity." And since it was cybersecurity, I even fell into the trap of trying to find excuses, thinking "maybe the vulnerability impact wasn't big enough." But boy, I was wrong. As soon as I stepped out, I noticed the silent patches, releases with no actual disclosure of what had been fixed, and no guidance on how organizations on older versions may be exposed. Cisco is expensive, and service contracts are not cheap. So realistically, a sysadmin or team leader just has to hope and pray that no bad actor pokes around, until they get the green light from a long approval process to upgrade.

Crazy as it sounds, the only thing we have are programs that the vendor can opt into. Not mandatory zero-day disclosure to the companies that actually need to know instantly so they can set their own risk parameters. I find it truly irresponsible. No vendor should ever set the risk parameters for another company.

You not wanting to look at the hole is your choice. But exposing other companies to liability because they are not aware because you chose to hide it, and then letting those companies fall into the hole? That is not alright. I would like to see red teamers  declare a network secure knowing there is undisclosed information out there.

What sickens me the most is how they use PR and other tactics to hide it. Look at the user Delco24 is clearly a vendor employee, or even worse, just a community sysadmin who tested before Cisco did. Think about that. Cisco has the resources to test every specific version immediately, they own the source code, they own the build pipeline, they can spin up any release in minutes. Instead, a random community member is doing their validation for them, and framing their answers to make others think the impact on their systems is low. That is exactly why I chose to release that particular vulnerability, I knew they were quietly patching. So I knew they were aware of the bug and were aware of researchers reports. That let me know they were choosing silence... working on bad faith...

So I am choosing to release on Monday at 23:59:00 UTC two CVSS 9+ vulnerabilities, they are so deeply rooted in CUCM and Expressway that they require a rewire to fix. And most importantly, I told you. The SIP parser on Expressway has fundamental problems, and no amount of hardening can fix the underlying issue. So tell me, was I crazy? Did I end up knowing what I was talking about? Right now there are around 1,300+ Expressway deployments exposing SIP on ports 5060/5061 in Shodan's internet-facing index, all vulnerable. The worst part? Bad actors probably have had this for months.

And for you Engineer, HelpDesk, Ops, Dev, remember: you won't be able to report what you don't know about. But if you send the email now, your ass is covered. It becomes someone else's problem up the chain. Without documentation or disclosure, you're the one left holding the hot potato.

How to detect manipulation and PR bots:

  1. Ask yourself: do you want to know if someone is f***ng with your network at Day 0 or Day 90?
  2. If someone is trying to convince you otherwise, goto 1.
reddit.com
u/0xReadingSteiner — 14 days ago

Two days ago I dropped a CVSS 10.0 pre-auth RCE chain on Cisco CUCM (Silent;Call). Today I'm releasing the tool that shows what happens next - and it's worse than the RCE itself. - FG#001 Phantom-Phone-Tap is LIVE NOW

Two days ago I published **Silent;Call** — a pre-authentication remote root chain on Cisco Unified Communications Manager 15.x. Three HTTP requests, zero credentials, root access. CVSS 10.0.

https://github.com/0xReadingSteiner/Silent-Call

The response I keep hearing: "OK, so you get root on a phone server. What's the actual impact?"

So I built the answer.

FG#001 — Phantom Phone Tap demonstrates exactly what an attacker does after landing on CUCM. The post-exploitation is worse than the initial compromise — because CUCM was designed to do all of this. No additional exploits. No malware. No logs.

https://github.com/0xReadingSteiner/FG001-phantom-phone-tap

---

What a compromised CUCM gives an attacker

TAP — Silent Call Interception

Silently join any active phone call in the enterprise. Both sides stream to you in real-time. Recorded and transcribed. Neither party gets any indication — no beep, no light, no notification. Built-In Bridge was designed for "call quality monitoring." It's a wiretap.

SPY — Room Surveillance

Turn any IP phone into a live room microphone. The speakerphone activates silently — no ring, no screen change, no LED. Every conference room and executive office becomes a listening post.

Track — Communication Intelligence

Full call history for any extension. Who called whom, when, for how long, from which device. Map communication patterns across the entire org.

Org — Cross-Cluster Worm

Enumerate the entire cluster. Every phone, every user, every trunk. Surface high-value targets by title — CEO, CFO, General Counsel. Enable wiretap on every phone in the enterprise with one SQL UPDATE. Zero audit trail.

And the worst part: it doesn't stop at one cluster. Org discovers other CUCM clusters via SIP trunk OPTIONS pings — intercluster trunks, B2B trunks to partner orgs, PSTN trunks to telcos. Each discovered CUCM gets fingerprinted and tested against the same Silent;Call chain. Same hardcoded creds. Same pre-auth RCE. Same root.

A hospital trunked to a clinic. A law firm trunked to a client. A government agency trunked to a contractor. A carrier trunked to hundreds of enterprises. One compromised CUCM worms through the entire trunk mesh.

---

# Your privacy is already gone

This isn't theoretical. If any CUCM in the trunk mesh is compromised, everyone on the other end loses their privacy protections — and they'll never know.

Regular Americans — your calls through any enterprise, hospital, or government office running CUCM can be silently intercepted. No notification. No consent. No recourse.

Senators and Congress members — your office phones, committee rooms, Capitol Hill lines all route through CUCM. Classified briefings, legislative negotiations — interceptable without a warrant, without FISA, without oversight.

Lawyers — attorney-client privilege ceases to exist on a compromised CUCM. Opposing counsel or a state actor could be listening to your case strategy in real-time. Your client's Sixth Amendment right to counsel — gone.

Doctors and healthcare workers — every patient call over a Cisco IP phone becomes a HIPAA violation the moment that CUCM is compromised. Protected Health Information flowing through intercepted calls. Federal penalties up to $1.5M per violation category per year.

Financial sector — intercepted executive calls expose material non-public information. That's insider trading fuel. Gramm-Leach-Bliley requires you to protect customer financial data — your phone system just handed it away.

Federal laws this violates:

- Wiretap Act (18 U.S.C. § 2511) — silent interception is a federal felony, up to 5 years per count
- ECPA — real-time interception and CDR exfiltration both covered
- HIPAA — intercepted medical calls expose Protected Health Information
- GLBA — financial customer data exposed via intercepted calls
- SOX — compromised executive communications enable insider trading
- FERPA — student records discussed over university CUCM phones
- Fourth Amendment — warrantless surveillance on government CUCM deployments
- CALEA — CUCM's own lawful intercept features used WITHOUT court authorization
- State wiretap laws — criminal offense in 12 all-party-consent states: CA, FL, IL, MD, MA, PA, CT, WA, OR, MT, NH, HI

Cisco claims 300,000+ CUCM deployments worldwide. The US federal government is one of their largest customers. Every military branch, most federal agencies, majority of the Fortune 500. When Silent;Call propagates through SIP trunks cluster to cluster, the entire US voice infrastructure built on Cisco is at risk.

This is not a vulnerability in a niche product. This is a vulnerability in the phone system.

---

# There is no detection

Silent;Call gives you root. That's bad. But the terrifying part is what root means on CUCM:

- There is no audit trail when Built-In Bridge is enabled via SQL
- There is no indicator on the phone when it's being tapped
- There is no SIEM event when auto-answer is activated remotely
- There is no detection mechanism for any of this

The wiretap capability is a feature — it just has no access controls, no logging, and no user notification.

---

# Sysadmins — check your exposure right now

Before you do anything else, run this on your CUCM CLI:

run sql select name, tkstatus_builtinbridge from device where tkclass = 1

Any phone showing tkstatus_builtinbridge = 2 has wiretap capability already enabled. If you didn't enable it, someone else did — or it's been on since deployment and nobody noticed.

The FG#001 README has a full 9-step hardening guide: SSH restriction, BIB auditing, voice VLAN segmentation, SQL monitoring, and what Cisco should provide but doesn't.

---

# Why I'm publishing this

Cisco PSIRT was notified. ZDI has 17 of my CUCM submissions sitting unprocessed. SSD paused all Cisco acquisitions because Cisco won't address existing reports. No CVEs assigned. No acknowledgment. No fix timeline.

This is advisory 1 of 55. Silent;Call is the entry point. FG#001 shows the impact. More kill chains are coming weekly.

Tool + hardening guide: https://github.com/0xReadingSteiner/FG001-phantom-phone-tap

Full research campaign: https://github.com/0xReadingSteiner/cisco-security-research

Contact: 0xReadingSteiner@proton.me

---

*FG#001 requires legitimate admin credentials (or the access Silent;Call provides). It does not introduce any new vulnerability — it demonstrates capabilities already present in every CUCM deployment.*

github.com
u/0xReadingSteiner — 14 days ago

Two days ago I dropped a CVSS 10.0 pre-auth RCE chain on Cisco CUCM (Silent;Call). Today I'm releasing the tool that shows what happens next - and it's worse than the RCE itself. - FG#001 Phantom-Phone-Tap is LIVE NOW

Two days ago I published **Silent;Call** — a pre-authentication remote root chain on Cisco Unified Communications Manager 15.x. Three HTTP requests, zero credentials, root access. CVSS 10.0.

https://github.com/0xReadingSteiner/Silent-Call

The response I keep hearing: "OK, so you get root on a phone server. What's the actual impact?"

So I built the answer.

FG#001 — Phantom Phone Tap demonstrates exactly what an attacker does after landing on CUCM. The post-exploitation is worse than the initial compromise — because CUCM was designed to do all of this. No additional exploits. No malware. No logs.

https://github.com/0xReadingSteiner/FG001-phantom-phone-tap

---

What a compromised CUCM gives an attacker

TAP — Silent Call Interception

Silently join any active phone call in the enterprise. Both sides stream to you in real-time. Recorded and transcribed. Neither party gets any indication — no beep, no light, no notification. Built-In Bridge was designed for "call quality monitoring." It's a wiretap.

SPY — Room Surveillance

Turn any IP phone into a live room microphone. The speakerphone activates silently — no ring, no screen change, no LED. Every conference room and executive office becomes a listening post.

Track — Communication Intelligence

Full call history for any extension. Who called whom, when, for how long, from which device. Map communication patterns across the entire org.

Org — Cross-Cluster Worm

Enumerate the entire cluster. Every phone, every user, every trunk. Surface high-value targets by title — CEO, CFO, General Counsel. Enable wiretap on every phone in the enterprise with one SQL UPDATE. Zero audit trail.

And the worst part: it doesn't stop at one cluster. Org discovers other CUCM clusters via SIP trunk OPTIONS pings — intercluster trunks, B2B trunks to partner orgs, PSTN trunks to telcos. Each discovered CUCM gets fingerprinted and tested against the same Silent;Call chain. Same hardcoded creds. Same pre-auth RCE. Same root.

A hospital trunked to a clinic. A law firm trunked to a client. A government agency trunked to a contractor. A carrier trunked to hundreds of enterprises. One compromised CUCM worms through the entire trunk mesh.

---

# Your privacy is already gone

This isn't theoretical. If any CUCM in the trunk mesh is compromised, everyone on the other end loses their privacy protections — and they'll never know.

Regular Americans — your calls through any enterprise, hospital, or government office running CUCM can be silently intercepted. No notification. No consent. No recourse.

Senators and Congress members — your office phones, committee rooms, Capitol Hill lines all route through CUCM. Classified briefings, legislative negotiations — interceptable without a warrant, without FISA, without oversight.

Lawyers — attorney-client privilege ceases to exist on a compromised CUCM. Opposing counsel or a state actor could be listening to your case strategy in real-time. Your client's Sixth Amendment right to counsel — gone.

Doctors and healthcare workers — every patient call over a Cisco IP phone becomes a HIPAA violation the moment that CUCM is compromised. Protected Health Information flowing through intercepted calls. Federal penalties up to $1.5M per violation category per year.

Financial sector — intercepted executive calls expose material non-public information. That's insider trading fuel. Gramm-Leach-Bliley requires you to protect customer financial data — your phone system just handed it away.

Federal laws this violates:

- Wiretap Act (18 U.S.C. § 2511) — silent interception is a federal felony, up to 5 years per count
- ECPA — real-time interception and CDR exfiltration both covered
- HIPAA — intercepted medical calls expose Protected Health Information
- GLBA — financial customer data exposed via intercepted calls
- SOX — compromised executive communications enable insider trading
- FERPA — student records discussed over university CUCM phones
- Fourth Amendment — warrantless surveillance on government CUCM deployments
- CALEA — CUCM's own lawful intercept features used WITHOUT court authorization
- State wiretap laws — criminal offense in 12 all-party-consent states: CA, FL, IL, MD, MA, PA, CT, WA, OR, MT, NH, HI

Cisco claims 300,000+ CUCM deployments worldwide. The US federal government is one of their largest customers. Every military branch, most federal agencies, majority of the Fortune 500. When Silent;Call propagates through SIP trunks cluster to cluster, the entire US voice infrastructure built on Cisco is at risk.

This is not a vulnerability in a niche product. This is a vulnerability in the phone system.

---

# There is no detection

Silent;Call gives you root. That's bad. But the terrifying part is what root means on CUCM:

- There is no audit trail when Built-In Bridge is enabled via SQL
- There is no indicator on the phone when it's being tapped
- There is no SIEM event when auto-answer is activated remotely
- There is no detection mechanism for any of this

The wiretap capability is a feature — it just has no access controls, no logging, and no user notification.

---

# Sysadmins — check your exposure right now

Before you do anything else, run this on your CUCM CLI:

run sql select name, tkstatus_builtinbridge from device where tkclass = 1

Any phone showing tkstatus_builtinbridge = 2 has wiretap capability already enabled. If you didn't enable it, someone else did — or it's been on since deployment and nobody noticed.

The FG#001 README has a full 9-step hardening guide: SSH restriction, BIB auditing, voice VLAN segmentation, SQL monitoring, and what Cisco should provide but doesn't.

---

# Why I'm publishing this

Cisco PSIRT was notified. ZDI has 17 of my CUCM submissions sitting unprocessed. SSD paused all Cisco acquisitions because Cisco won't address existing reports. No CVEs assigned. No acknowledgment. No fix timeline.

This is advisory 1 of 55. Silent;Call is the entry point. FG#001 shows the impact. More kill chains are coming weekly.

Tool + hardening guide: https://github.com/0xReadingSteiner/FG001-phantom-phone-tap

Full research campaign: https://github.com/0xReadingSteiner/cisco-security-research

Contact: 0xReadingSteiner@proton.me

---

*FG#001 requires legitimate admin credentials (or the access Silent;Call provides). It does not introduce any new vulnerability — it demonstrates capabilities already present in every CUCM deployment.*https://github.com/0xReadingSteiner/FG001-phantom-phone-tap

u/0xReadingSteiner — 14 days ago