PT-2026-45420 · Poly · Vvx 250+6
Published
2026-06-01
·
Updated
2026-06-02
·
CVE-2026-0826
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Poly Voice VVX 150
Poly Voice VVX 250
Poly Voice VVX 350
Poly Voice VVX 450
Poly Voice Trio 8300
Poly Voice Trio 8500
Poly Voice Trio 8800
Description
A stack-based buffer overflow exists in Poly Voice products on the Linux platform during the parsing of Session Description Protocol (SDP) attributes. The issue occurs specifically within the
ParseICECandidate() function when the Interactive Connectivity Establishment (ICE) feature is enabled. An unauthenticated attacker can exploit this by sending a malicious SIP INVITE request to UDP port 5060 containing an oversized a=candidate: attribute. This triggers a 256-byte buffer overflow via memcpy() without bounds checking in /user/local/root/polyapp, allowing the attacker to bypass NX protection using a ROP chain and execute remote code with root privileges. This could lead to unauthorized access to enterprise networks, eavesdropping, and lateral movement.Recommendations
Update the firmware for VVX 150, VVX 250, VVX 350, VVX 450, Trio 8300, Trio 8500, and Trio 8800 to the latest patched version.
As a temporary mitigation, disable the Interactive Connectivity Establishment (ICE) feature if it is not required.
Fix
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trio 8300
Trio 8500
Trio 8800
Vvx 150
Vvx 250
Vvx 350
Vvx 450