PT-2026-45420 · Poly · Vvx 150+6
CVE-2026-0826
·
Published
2026-06-01
·
Updated
2026-06-23
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
HP Poly VVX 150
HP Poly VVX 250
HP Poly VVX 350
HP Poly VVX 450
HP Poly Trio 8300
HP Poly Trio 8500
HP Poly Trio 8800
Description
An unauthenticated stack-based buffer overflow exists in HP Poly Voice products on the Linux platform during the parsing of Session Description Protocol (SDP) attributes. The issue occurs specifically within the
ParseICECandidate() function when the Interactive Connectivity Establishment (ICE) feature is enabled. A remote attacker can exploit this by sending a malicious SIP INVITE request to UDP port 5060 containing an oversized a=candidate: attribute. This triggers a 256-byte buffer overflow via memcpy() without bounds checking in /user/local/root/polyapp, allowing the attacker to bypass NX protection using a ROP chain and execute arbitrary code with root privileges. This could enable eavesdropping and lateral movement within an enterprise network.Recommendations
Apply the fixed firmware update for VVX 150, VVX 250, VVX 350, VVX 450, Trio 8300, Trio 8500, and Trio 8800.
As a temporary mitigation, disable the Interactive Connectivity Establishment (ICE) feature if it is not required.
Restrict VoIP device management access using network segmentation and IP allowlisting.
Remove default credentials and enforce secure configuration baselines.
Separate VoIP systems from critical business systems to reduce the risk of lateral movement.
Fix
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trio 8300
Trio 8500
Trio 8800
Vvx 150
Vvx 250
Vvx 350
Vvx 450