CVE-2025-14432: HP Poly Tcos
Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.
In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI.
Affected products
- HP Poly Tcos: before 6.6.1-7001859 (fixed in 6.6.1-7001859)
- HP Poly Videoos: before 4.6.1-444242 (fixed in 4.6.1-444242)
Published 2025-12-16. Last modified 2026-10-07.