Executive brief
Mitel 6800, 6900, and 6900w Series SIP phones contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. An authenticated attacker with administrative privileges can exploit this to execute arbitrary commands within the context of the system.
Affected products
- Mitel 6800 Series SIP Phones through R6.4.0.HF1 (R6.4.0.136)
- Mitel 6900 Series SIP Phones through R6.4.0.HF1 (R6.4.0.136)
- Mitel 6900w Series SIP Phones through R6.4.0.HF1 (R6.4.0.136)
- Mitel 6970 Conference Unit through R6.4.0.HF1 (R6.4.0.136)
Timeline
- 2025-02-12: disclosed
- 2025-02-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-02-12: exploited: Reported as exploited in the wild per CISA KEV inclusion.