Executive brief
HP Poly IP phones are vulnerable to a security flaw where malicious data stored in configuration settings can be executed by the device's web management interface. An attacker with low-level access could use this to manipulate the phone's web interface, potentially leading to unauthorized configuration changes or session hijacking. This affects Poly CCX, Edge E, and Trio C60 models, and users should update to the latest firmware to resolve the issue.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in HP Poly IP phones (CCX, Edge E, and Trio C60). The vulnerability, classified as CWE-79, occurs because the device's WebUI fails to properly neutralize malicious input stored within configuration parameters before rendering it on a webpage. An attacker with network access and low privileges (PR:L) could inject malicious scripts that execute in the context of a user's browser when they view the affected configuration page. This could lead to unauthorized actions or data theft within the management session. The issue is addressed in Poly CCX and Trio C60 versions 9.5.0 and later, and Poly Edge E version 8.6.0 and later.
Affected products
- HP Inc. Poly CCX Before 9.5.0
- HP Inc. Poly Edge E Before 8.6.0
- HP Inc. Poly Trio C60 Before 9.5.0
Timeline
- 2026-07-08: advisory
- 2026-07-08: disclosed