CVE-2026-0754: SIP Service Providers – Possible Impersonation of Poly Voice Device
An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering tools. This extracted certificate could be accepted by a SIP service provider if the service provider does not perform proper validation of the device certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0754?
CVE-2026-0754 is considered a high severity vulnerability due to the potential for impersonation of Poly Voice devices.
How do I fix CVE-2026-0754?
To mitigate CVE-2026-0754, ensure that your Poly Voice device firmware is updated to the latest version provided by Poly.
What types of devices are affected by CVE-2026-0754?
CVE-2026-0754 specifically affects Poly Voice devices that utilize embedded test keys and certificates.
What are the risks associated with CVE-2026-0754?
The primary risk of CVE-2026-0754 is the possibility of unauthorized impersonation of Poly Voice devices by malicious actors.
Is there a workaround for CVE-2026-0754?
While updating firmware is the primary solution for CVE-2026-0754, additional network security measures should also be employed to limit unauthorized access.