CVE-2026-0754 Details
Description
An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering tools. This extracted certificate could be accepted by a SIP service provider if the service provider does not perform proper validation of the device certificate.
A vulnerability exists in certain Poly Voice devices, allowing an embedded test key and certificate to be extracted through specialized reverse engineering tools. If this certificate is obtained, it could be accepted by a SIP service provider that fails to properly validate device certificates, potentially leading to unauthorized impersonation of the Poly Voice device.
Service providers should ensure full validation of certificates before provisioning Poly Voice devices, including checking the certificate revocation status and validating the Common Name in the Subject Name field. Affected Poly Voice devices should be updated to the latest PVOS or UCS release using the Poly Lens Device Management App.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hp.com/us-en/document/ish_14269649-14269682-16/hpsbpy04081 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 3, 2026 | New CVE Received | [email protected] |