Impact
The flaw allows malicious input stored in configuration parameters to be rendered by the device’s WebUI. When an attacker can inject script code, the request is subsequently displayed to users, enabling unauthorized changes to the interface and potential malicious actions. The weakness aligns with CWE-79, describing reflected cross-site scripting and could let an attacker hijack sessions or execute commands through the browser.
Affected Systems
The vulnerability applies to HP Inc. Poly CCX, Poly Edge E, and Poly Trio C60 IP phones. No specific firmware or model revisions are listed, so all currently supported devices that expose the WebUI are potentially affected.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of < 1% indicates a very low exploitation probability, and the issue is not in the KEV catalog. Because the flaw relies on the WebUI, the likely attack vector is remote via the device’s management interface, though local injection through configuration changes is also possible if an attacker can alter system settings. An attacker who succeeds can alter the UI’s behavior, potentially enabling further attacks.
OpenCVE Enrichment