A simple exploit has been discovered that allows an attacker to leverage the weak default passwords of a Voice over IP (VoIP) phone in order to eavesdrop on conversations. Security consultant Paul Moore demonstrated that all an attacker needs to do is trick the VoIP user into visiting a malicious website on which an exploit payload is hosted. Moore urges that if vendors must ship devices with default credentials, then they must disable all other functionality until a suitably-secure password is set to replace it”]
Source: https://grahamcluley.com/voip-phone-spying-default-passwords/

