CVE-2018-17875: High severity poly firmware vulnerability

Published Dec 28, 2021
·
Updated

A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors.

Affected Software

22 affected components
Poly Trio 8800 Firmware=5.4.0.12197
Poly Trio 8800 Firmware=5.4.0.12541
Poly Trio 8800 Firmware=5.4.0.12856
Poly Trio 8800 Firmware=5.4.1.17597
Poly Trio 8800 Firmware=5.4.2.5400
Poly Trio 8800 Firmware=5.4.3.2007
Poly Trio 8800 Firmware=5.4.3.2389
Poly Trio 8800 Firmware=5.4.3.2400
Poly Trio 8800 Firmware=5.4.4.7511
Poly Trio 8800 Firmware=5.4.4.7609
Poly Trio 8800 Firmware=5.4.4.7776
Poly Trio 8800 Firmware=5.4.5.9111
Poly Trio 8800 Firmware=5.4.5.9658
Poly Trio 8800 Firmware=5.5.2.11338
Poly Trio 8800 Firmware=5.5.2.11391
Poly Trio 8800 Firmware=5.5.3.3441
Poly Trio 8800 Firmware=5.5.3.3517
Poly Trio 8800 Firmware=5.5.4.2255
Poly Trio 8800 Firmware=5.7.1.4095
Poly Trio 8800 Firmware=5.7.1.4133
Poly Trio 8800 Firmware=5.7.1.4145
Poly Trio 8800

Event History

Dec 28, 2021
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2018-17875?

CVE-2018-17875 is classified as a high-severity remote code execution vulnerability affecting Poly Trio 8800 devices.

2

How do I fix CVE-2018-17875?

To address CVE-2018-17875, update the Poly Trio 8800 firmware to a version that has patched this vulnerability.

3

Who is affected by CVE-2018-17875?

CVE-2018-17875 affects devices running specific vulnerable versions of Poly Trio 8800 firmware, particularly version 5.7.1.4145.

4

What type of vulnerability is CVE-2018-17875?

CVE-2018-17875 is a remote code execution vulnerability, allowing attackers to execute arbitrary commands.

5

Can CVE-2018-17875 be exploited remotely?

Yes, CVE-2018-17875 can be exploited by remote authenticated users to execute commands on the affected devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203