logo

Why an HP Poly VoIP Phones Bug Could Become an Enterprise Foothold

ID: cfc6861a-e6e3-5291-a8fa-fb8600c6f646

STIX ID: report--cfc6861a-e6e3-5291-a8fa-fb8600c6f646

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Pierluigi Paganini

...
...

Rapid7 disclosed CVE-2026-0826, a critical unauthenticated stack-buffer overflow in SDP parsing on HP Poly VVX and Trio VoIP phones that enables remote root RCE via specially crafted SIP INVITE messages containing oversized ICE candidate attributes; the report details memory corruption, practical ROP bypass of NX, affected models/firmware, and recommends disabling ICE and applying vendor patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.