CVE-2026-5922 Details
Description
The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpage.
A cross-site scripting vulnerability has been identified in HP Poly Voice IP phones. This issue arises because the phone's WebUI can render malicious input that has been stored in configuration parameters, potentially allowing for unauthorized modification of the webpage content.
HP has released updates to address this vulnerability. Affected users should update to version 9.5.0 for CCX and Trio C60 models, and version 8.6.0 for Edge E models.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hp.com/us-en/document/ish_15255534-15255565-16/hpsbpy04108 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |