ZeroHour
Security Affairspublished ()ingested @securityaffairs

Aquabot variant v3 targets Mitel SIP phones

mediumExploit / PoCimportance 50CVE-2024-41710

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-41710
Argument Injection RCE in Mitel 6800/6900/6900w Series SIP Phones

CVE-2024-41710 is an argument injection vulnerability (CWE-88) affecting Mitel 6800 Series, 6900 Series, and 6900w Series SIP phones, including the 6970 Conference Unit, caused by insufficient sanitization of parameters processed during the device's boot process. An attacker who can supply crafted arguments to the boot process can inject and execute arbitrary commands within the context of the phone's system. Organizations deploying these enterprise desk phones are affected; the available data does not specify affected or fixed firmware version ranges. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-02-12, confirming exploitation in the wild, though no public proof-of-concept is known and any ransomware association is unconfirmed. EPSS assigns a 41.6% probability of exploitation within the next 30 days (99th percentile), so remediation should be treated as urgent.

Do: Update affected 6800/6900/6900w series phones to the fixed firmware per Mitel's security advisory and reboot the phones so they boot with patched firmware, since the flaw is in the boot process; if fixed firmware is unavailable, apply Mitel's mitigations or discontinue use per the CISA KEV required action. Check whether phone management or provisioning interfaces are reachable from untrusted networks and restrict that access. Given KEV-listed exploitation and a 99th-percentile EPSS score, prioritize remediation, and note federal agencies are required to act under the KEV deadline.

7.242% KEV PoC
  • Mitel 6800 Series SIP Phones
  • Mitel 6900 Series SIP Phones
  • Mitel 6900w Series SIP Phones
  • +1 more
largeon the order of 100,000+ deployed handsets globally (enterprise VoIP installed base estimate; internet-exposed subset likely smaller)

Indicators of compromiseAll →

TypeIndicatorContext
ipv46.4.0.136es, including the 6970 Conference Unit through R6.4.0.HF1 (R6.4.0.136). In mid-July 2024, Mitel addressed the vulnerability with
Full article546 words · extracted from securityaffairs.com · click to collapse

A new variant of the Mirai-based botnet Aquabot targets vulnerable Mitel SIP phones to recruit them into a DDoS botnet.

Akamai researchers spotted a new variant of the Mirai-based botnet Aquabot that is targeting vulnerable Mitel SIP phones.

Aquabot is a Mirai-based botnet designed for DDoS attacks. Named after the “Aqua” filename, it was first reported in November 2023.

As this is the third distinct iteration of Aquabot, Akamai tracked this variant as Aquabotv3. The bot targets the command injection vulnerability CVE-2024-41710 that impacts Mitel models.

“This third iteration adds a novel activity for a Mirai-based botnet: C2 communication when the botnet catches certain signals.” reads the report published by Akamai. “This, and other notable differences in functionality, separate the two versions significantly, supporting the distinction of a third variant.”

The malware targets the flaw CVE-2024-41710 that affects Mitel 6800, 6900, and 6900w series SIP phones, including the 6970 Conference Unit through R6.4.0.HF1 (R6.4.0.136).

In mid-July 2024, Mitel addressed the vulnerability with the release of firmware updates. The vendor warned that the exploitation of the flaw “could allow an authenticated attacker with administrative privilege to conduct a command injection attack due to insufficient parameter sanitization during the boot process”.

A month later, the PacketLabs researcher Kyle Burns published a PoC exploit code for the vulnerability CVE-2024-41710.

Akamai states that there are not report of attacks exploiting this vulnerability in the wild prior to the SIRT’s observations in January 2025.

“The exploit proof of concept (PoC) shows us that an attacker could smuggle in entries otherwise blocked by the application’s sanitization checks by sending a specially crafted HTTP POST request.” continues the report. “In his GitHub README, Burns reported that he found that the Mitel 6869i SIP phone, firmware version 6.3.0.1020, failed to sanitize user-supplied input properly, and he found multiple endpoints vulnerable to this. For the PoC, he focused on the endpoint “802.1x Support” (8021xsupport.html).”

This malware exhibits a unique behavior for a Mirai variant, it includes a function (report_kill) that reports to the command and control server when a kill signal is detected on the infected device.

aquabot botnet

Like other botnets, Aquabot v3 targets additional vulnerabilities in various products, including Hadoop YARN, the Roxy-WI web interface, and routers from Linksys, Teltonika, Dasan GPON, and LB-LINK.

The threat actors behind Aquabot have been advertising it as a DDoS-as-a-service on platforms like Telegram under various misleading names, such as Cursinq Firewall and The Eye Botnet. They often claim it is for DDoS mitigation testing, but experts pointed out that it spreads Mirai malware and is used for real attacks.

“In the case of Aquabot, the core malware is the same as Mirai but the signal handling is particularly unique. Unique, however, is not always the most useful — this malware was not particularly quiet, which could be to its detriment.” concludes the report that includes Indicators of Compromise (IoCs).

“The reason for the unique signal handling could be that the threat actor is intentionally observing a machine’s defensive activity to develop more stealthy variants in the future. It could also be used to detect active disruption/attacks from competing botnets or ethical take down campaigns, or any combination thereof.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Mirai)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/173607/breaking-news/aquabot-variant-v3-targets-mitel-sip-phones.html