CVE-2026-0791
8.1ALGO · 8180 IP Audio Alerter
A stack-based buffer overflow in the ALGO 8180 IP Audio Alerter allows unauthenticated remote attackers to execute arbitrary code via a crafted SIP INVITE request.
Executive summary
The ALGO 8180 IP Audio Alerter is vulnerable to a remote code execution flaw that permits unauthenticated attackers to compromise device integrity.
Vulnerability
This is a stack-based buffer overflow (CWE-121) occurring in the SIP INVITE handling process. An unauthenticated attacker can trigger this by sending a specially crafted Replaces header to the device, causing memory corruption that leads to remote code execution.
Business impact
Successful exploitation of this vulnerability allows an attacker to gain full control over the affected audio alerter device. This poses a significant risk to organizational communications and physical security systems, potentially leading to unauthorized system access or the disruption of critical alerting services. Given the CVSS score of 8.1, this represents a high-severity threat that requires immediate attention to prevent device compromise.
Remediation
Immediate Action: Contact the vendor or monitor the official ALGO support portal for the release of firmware version 5.5.1 or higher, as a patch is currently unknown.
Proactive Monitoring: Review SIP traffic and device access logs for malformed INVITE requests or unusual patterns associated with the Replaces header.
Compensating Controls: Restrict access to the device management interface and SIP signaling ports to trusted internal networks only, utilizing network segmentation or a firewall to block unauthorized external SIP traffic.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Because this vulnerability allows for unauthenticated remote code execution, it presents a substantial risk to the availability and integrity of your audio infrastructure. Organizations should immediately audit their network exposure for these devices and implement strict network-level access controls until an official firmware patch is provided by the manufacturer.