PT-2026-45420 · Poly · Vvx 150+6

CVE-2026-0826

·

Published

2026-06-01

·

Updated

2026-06-23

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions HP Poly VVX 150 HP Poly VVX 250 HP Poly VVX 350 HP Poly VVX 450 HP Poly Trio 8300 HP Poly Trio 8500 HP Poly Trio 8800
Description An unauthenticated stack-based buffer overflow exists in HP Poly Voice products on the Linux platform during the parsing of Session Description Protocol (SDP) attributes. The issue occurs specifically within the ParseICECandidate() function when the Interactive Connectivity Establishment (ICE) feature is enabled. A remote attacker can exploit this by sending a malicious SIP INVITE request to UDP port 5060 containing an oversized a=candidate: attribute. This triggers a 256-byte buffer overflow via memcpy() without bounds checking in /user/local/root/polyapp, allowing the attacker to bypass NX protection using a ROP chain and execute arbitrary code with root privileges. This could enable eavesdropping and lateral movement within an enterprise network.
Recommendations Apply the fixed firmware update for VVX 150, VVX 250, VVX 350, VVX 450, Trio 8300, Trio 8500, and Trio 8800. As a temporary mitigation, disable the Interactive Connectivity Establishment (ICE) feature if it is not required. Restrict VoIP device management access using network segmentation and IP allowlisting. Remove default credentials and enforce secure configuration baselines. Separate VoIP systems from critical business systems to reduce the risk of lateral movement.

Fix

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-0826

Affected Products

Trio 8300
Trio 8500
Trio 8800
Vvx 150
Vvx 250
Vvx 350
Vvx 450