Mitel Networks has released security updates to fix a critical authentication bypass flaw affecting its MiVoice MX-ONE.
See also: Critical flaw in Nvidia Toolkit exposes AI Cloud services

MX-ONE is a SIP-based communication system that can be expanded to support hundreds of thousands of users.
This critical flaw is due to an access control vulnerability identified in the MiVoice MX-ONE Provisioning Manager and currently has no CVE identifier assigned. Unidentified attackers can exploit it through low-sophistication attacks, without requiring user interaction, to gain unauthorized access to administrator accounts on unpatched systems.
According to Mitel, the vulnerability affects MiVoice MX-ONE versions 7.3 (7.3.0.0.50) to 7.8 SP1 (7.8.1.0.14) and has been fixed in versions 7.8 (MXO-15711_78SP0) and 7.8 SP1 (MXO-15711_78SP1).
Customers using MiVoice MX-ONE version 7.3 or later are advised to submit a patch request through their authorized support partner.
See also: Critical D-Link flaw leads to server crash
Today, Mitel disclosed a SQL injection (CVE-2025-52914) in its MiCollab, which can be exploited to execute arbitrary SQL database commands on unpatched devices.

While there are no reports that these two vulnerabilities have been actively exploited, CISA had warned US federal agencies about a path traversal vulnerability in MiCollab (CVE-2024-55550), which was used in attacks and allowed authenticated attackers with administrative privileges to read arbitrary files from vulnerable servers.
A month earlier, the company had fixed a zero-day vulnerability in MiCollab for reading arbitrary files (CVE-2024-41713), discovered by the research team watchTowr Labs and could allow attackers to gain access to file system .
See also: New flaw in ServiceNow allows data extraction
Mitel products are used by more than 60,000 customers and over 75 million users in various sectors, such as education, healthcare, financial services, industry and the public sector.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
