Why an HP Poly VoIP Phones Bug Could Become an Enterprise Foothold
ID: cfc6861a-e6e3-5291-a8fa-fb8600c6f646
STIX ID: report--cfc6861a-e6e3-5291-a8fa-fb8600c6f646
Feed Name: Security Affairs
Threat Score
Rapid7 disclosed CVE-2026-0826, a critical unauthenticated stack-buffer overflow in SDP parsing on HP Poly VVX and Trio VoIP phones that enables remote root RCE via specially crafted SIP INVITE messages containing oversized ICE candidate attributes; the report details memory corruption, practical ROP bypass of NX, affected models/firmware, and recommends disabling ICE and applying vendor patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
