HP VoIP Phones Vulnerability Allows Enterprise Network Breaches
TL;DR. A critical vulnerability in several HP Poly Voice VoIP phone models enables remote code execution with root privileges, threatening enterprise networks. - The bug, CVE-2026-0826, is a stack-based buffer overflow in ICE feature parsing. - Exploitation involves sending a malicious SIP INVITE request with a crafted candidate attribute. - Patches are available, and disabling ICE where unnecessary can mitigate the risk.
- HP Poly Voice VoIP phones have a critical remote code execution vulnerability (CVE-2026-0826).
- The flaw allows attackers to gain root privileges and access enterprise networks.
- Exploitation involves a stack-based buffer overflow during Session Description Protocol (SDP) parsing.
- HP has released patches for affected VVX series and Trio IP Conference series models.
Sources
- Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches — securityweek.com