Executive brief
A security vulnerability exists in several HP Poly IP phone models, including the CCX, Edge E, and Trio C60 series. If an attacker manages to obtain a user's session cookie, they could modify the settings or content of the phone's web management interface. This could lead to unauthorized changes in device configuration or disruption of phone services.
Technical details
This vulnerability is classified as Cross-Site Request Forgery (CSRF) (CWE-352) affecting the web management interface of HP Poly IP phones. The flaw allows an attacker who has obtained a valid session cookie to perform unauthorized actions or modify the contents of the phone's webpage. Exploitation requires network access, low privileges, and some level of user interaction. The vulnerability affects Poly CCX versions prior to 9.50, Poly Edge E versions prior to 8.6.0, and Poly Trio C60 versions prior to 9.5.0. Users are advised to update to the latest firmware versions provided by HP.
Affected products
- HP Inc. Poly CCX < 9.50
- HP Inc. Poly Edge E < 8.6.0
- HP Inc. Poly Trio C60 < 9.5.0
Timeline
- 2026-07-08: disclosed: Initial publication of CVE-2026-5923