CVE-2021-41322: Polycom Vvx 400 Firmware

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password reset process.

Affected products

  • Polycom Vvx 400 Firmware: version 5.3.1 only
  • Polycom Vvx 410 Firmware: version 5.3.1 only

Published 2021-10-04. Last modified 2026-06-17.