CVE-2026-0754

Severity CVSS v4.0:
HIGH
Type:
CWE-321 Use of Hard-coded Cryptographic Key
Publication date:
03/03/2026
Last modified:
03/03/2026

Description

An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering tools. This extracted certificate could be accepted by a SIP service provider if the service provider does not perform proper validation of the device certificate.