CVE-2025-47187: Malicious File Upload
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 SP4 (R6.4.0.4006) or version V1 R0.1.0, could allow an unauthenticated attacker to perform a file upload attack due to missing authentication mechanisms. A successful exploit could allow an attacker to upload arbitrary WAV files, which may potentially exhaust the phone’s storage without affecting the phone's availability or operation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47187?
CVE-2025-47187 is considered a high-severity vulnerability due to its potential for unauthenticated file upload attacks.
How do I fix CVE-2025-47187?
To fix CVE-2025-47187, update the affected Mitel SIP Phones and Conference Unit firmware to a version beyond 6.4 SP4.
What systems are affected by CVE-2025-47187?
CVE-2025-47187 affects the Mitel 6800 Series, 6900 Series, 6900w Series SIP Phones, and the 6970 Conference Unit, all up to firmware version 6.4 SP4.
What does CVE-2025-47187 allow an attacker to do?
CVE-2025-47187 allows an unauthenticated attacker to perform a file upload attack, potentially compromising the device.
Is there a workaround for CVE-2025-47187?
Currently, the only reliable mitigation for CVE-2025-47187 is to upgrade to the latest firmware version that addresses the vulnerability.