CVE-2025-47188
largeUnauthenticated Command Injection in Mitel 6800/6900 Series SIP Phones
CVE-2025-47188 is an unauthenticated command injection flaw (CWE-77) in the firmware of Mitel 6800 Series, 6900 Series, and 6900w Series SIP phones and the 6970 Conference Unit, caused by insufficient sanitization of parameters passed to a network-reachable service. Because the vector requires no authentication and no user interaction, a remote attacker able to reach the phone can send crafted parameters that trigger execution of arbitrary commands on the device. A successful exploit lets the attacker read or modify sensitive configuration data (such as provisioning details or credentials stored on the phone) or disrupt the device's availability and operation. Organizations running these Mitel desk phone and conference unit models on any firmware up to and including 6.4 SP4 (R6.4.0.4006), or version V1 R0.1.0 for the 6970 Conference Unit, are affected. The flaw is not yet on the CISA KEV list and no public proof-of-concept is known, but its EPSS score of roughly 50% (99th percentile) indicates an elevated likelihood of exploitation appearing in the wild within 30 days.
What to do: Upgrade affected phones and 6970 Conference Units to a firmware release later than 6.4 SP4 (R6.4.0.4006), and later than V1 R0.1.0 for the 6970 Conference Unit, following Mitel's security advisory for the exact fixed builds. Until patched, restrict network access to the phones' management/provisioning interfaces (e.g., keep them off the internet, limit access to trusted management subnets, and segment voice VLANs from user networks). Inventory which sites run these models, and watch for updated EPSS/KEV status since the ~50% EPSS score signals material exploitation risk in the near term.
| Mitel 6800 Series SIP Phones | through 6.4 SP4 (R6.4.0.4006) |
| Mitel 6900 Series SIP Phones | through 6.4 SP4 (R6.4.0.4006) |
| Mitel 6900w Series SIP Phones | through 6.4 SP4 (R6.4.0.4006) |
| Mitel 6970 Conference Unit | through 6.4 SP4 (R6.4.0.4006) and version V1 R0.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 SP4 (R6.4.0.4006) or version V1 R0.1.0, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the context of the phone, leading to disclosure or modification of sensitive configuration data or affecting device availability and operation.
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N