PT-2026-45420 · Poly · Vvx 250+6

Published

2026-06-01

·

Updated

2026-06-02

·

CVE-2026-0826

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Poly Voice VVX 150 Poly Voice VVX 250 Poly Voice VVX 350 Poly Voice VVX 450 Poly Voice Trio 8300 Poly Voice Trio 8500 Poly Voice Trio 8800
Description A stack-based buffer overflow exists in Poly Voice products on the Linux platform during the parsing of Session Description Protocol (SDP) attributes. The issue occurs specifically within the ParseICECandidate() function when the Interactive Connectivity Establishment (ICE) feature is enabled. An unauthenticated attacker can exploit this by sending a malicious SIP INVITE request to UDP port 5060 containing an oversized a=candidate: attribute. This triggers a 256-byte buffer overflow via memcpy() without bounds checking in /user/local/root/polyapp, allowing the attacker to bypass NX protection using a ROP chain and execute remote code with root privileges. This could lead to unauthorized access to enterprise networks, eavesdropping, and lateral movement.
Recommendations Update the firmware for VVX 150, VVX 250, VVX 350, VVX 450, Trio 8300, Trio 8500, and Trio 8800 to the latest patched version. As a temporary mitigation, disable the Interactive Connectivity Establishment (ICE) feature if it is not required.

Fix

RCE

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-0826

Affected Products

Trio 8300
Trio 8500
Trio 8800
Vvx 150
Vvx 250
Vvx 350
Vvx 450