Poly manufactures a portfolio of business communication devices and unified communication endpoints, including its Trio and CCX series of conference phones and desk devices, which are embedded across enterprise meeting infrastructures. The recurring vulnerabilities affecting this vendor cluster around command and input-handling weaknesses—OS command injection, command injection, cross-site scripting, and hidden functionality—that are characteristic of network-connected embedded devices with web interfaces and administrative surfaces. A meaningful share of the vendor's disclosures reach serious severity; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Poly over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26482HIGH An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin. | Jul 17, 2022 | 7.2 | 34 | NO | NO |
CVE-2022-26479CRITICAL An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as adm | Jul 17, 2022 | 9.8 | 32 | NO | NO |
CVE-2018-17875HIGH A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors. | Dec 28, 2021 | 8.8 | 29 | NO | NO |
CVE-2022-26481HIGH An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action. | Jul 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-4468HIGH A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud | Dec 29, 2023 | 7.6 | 24 | NO | NO |
CVE-2023-4464HIGH A vulnerability, which was classified as critical, has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100 | Dec 29, 2023 | 7.2 | 24 | NO | NO |
CVE-2021-37145HIGH A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attacker to Privilege Escalation and Remote Code | Sep 7, 2021 | 7.2 | 24 | NO | NO |
CVE-2023-4463HIGH A vulnerability classified as problematic was found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60. This vulnerability affects unknown code of the component HTTP Header Handler. | Dec 29, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-4467MEDIUM A vulnerability was found in Poly Trio 8800 7.2.6.0019 and classified as critical. Affected by this issue is some unknown functionality of the component Test Automation Mode. The m | Dec 29, 2023 | 6.6 | 21 | NO | NO |
CVE-2023-4465MEDIUM A vulnerability, which was classified as problematic, was found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, | Dec 29, 2023 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Poly.
Media articles that mention a CVE ID that affects a product developed by Poly — matched by CVE ID, not by vendor name.