HP VoIP Phones Vulnerability Allows Enterprise Network Breaches

TL;DR. A critical vulnerability in several HP Poly Voice VoIP phone models enables remote code execution with root privileges, threatening enterprise networks. - The bug, CVE-2026-0826, is a stack-based buffer overflow in ICE feature parsing. - Exploitation involves sending a malicious SIP INVITE request with a crafted candidate attribute. - Patches are available, and disabling ICE where unnecessary can mitigate the risk.

Sources

Back to QLANKR News