https://www.theregister.com/2025/07/02/cisco_patch_cvss/
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssh-m4UBdpE7
If you’re running the Engineering-Special (ES) builds of Cisco Unified Communications Manager or its Session Management Edition, you need to apply Cisco’s urgent patch after someone at Switchzilla made a big mistake. … However, the ES builds of both packages have hardcoded credentials baked in, and they cannot be changed or deleted, meaning an unauthenticated, remote attacker can quickly get themselves full root control of a system if they know where to look. …
This an “Ooops!” or an “Awwww S**T!” Asking for a friend…
Regards