CVE-2026-0754
Severity CVSS v4.0:
HIGH
Type:
CWE-321
Use of Hard-coded Cryptographic Key
Publication date:
03/03/2026
Last modified:
03/03/2026
Description
An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering tools. This extracted certificate could be accepted by a SIP service provider if the service provider does not perform proper validation of the device certificate.
Impact
Base Score 4.0
8.20
Severity 4.0
HIGH



