CVE-2026-0794

8.1

ALGO · 8180 IP Audio Alerter

A use-after-free vulnerability in the ALGO 8180 IP Audio Alerter SIP handling allows unauthenticated remote attackers to achieve remote code execution.

Executive summary

The ALGO 8180 IP Audio Alerter contains a critical use-after-free vulnerability that allows unauthenticated remote code execution, posing a severe risk to device integrity.

Vulnerability

The flaw exists within the SIP call processing logic, specifically due to a failure to validate object existence before performing operations. This use-after-free vulnerability permits an unauthenticated attacker to execute arbitrary code in the context of the device.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain full control over the affected IP audio device. Given the CVSS score of 8.1, the high potential for total system compromise and the ability to execute arbitrary code remotely make this a significant security risk for organizations relying on these devices for communication or alerting infrastructure.

Remediation

Immediate Action: Contact the vendor immediately to obtain firmware updates for version 5.5, as a specific patch version is not currently identified in the enrichment data.

Proactive Monitoring: Monitor network traffic for unusual SIP signaling patterns or unexpected connection attempts directed at the audio alerter endpoints.

Compensating Controls: Restrict network access to the SIP interface of the device using firewall rules or VLAN segmentation to ensure that only authorized call servers can communicate with the hardware.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Due to the high severity of this remote code execution vulnerability, immediate attention is required. Administrators should verify the current firmware version of all ALGO 8180 devices and implement strict network access controls to isolate these systems from the public internet until a vendor-supplied patch can be successfully applied.

More ALGO CVEs

Sources