TL;DR

ALGO 8180 IP Audio Alerter devices are vulnerable to a command injection RCE via API. Auth is needed for exploitation; ZDI assigned CVE-2026-0785

What happened

['Remote attackers can execute arbitrary code on affected ALGO 8180 devices', 'Exploit requires authentication']

Why it matters for ops

['Critical infrastructure needs protection against RCE vulnerabilities', 'Command injection poses significant risk for unauthorized access and control']

Mitigation

  • Apply firmware updates provided by the manufacturer
  • Disable unused APIs and services
  • Implement strict access controls

Action items

  • Patch affected systems as soon as updates are available
  • Monitor for unusual network activity related to this vulnerability

Detection IOCs

  • Unusual network traffic to ALGO 8180 devices
  • Unexpected authentication attempts on the device's API

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-007/